Oregon Zoo Details

    Organization Logo

    Oregon Zoo

    Portland, Oregon employees • Civil Society and Non-Profits

    United States

    Industry

    Civil Society and Non-Profits

    Security Incidents

    1

    The Oregon Zoo, located in Portland, Oregon, is a prominent institution focused on connecting communities to the wonder of wildlife to foster a better future for all. Established in 1888, the zoo has a deep history of community support and plays a vital role as a hub for science, conservation, education, and animal well-being. The zoo is home to 165 species and subspecies, delivering the highest quality care to its animal residents.

    The zoo is a part of Metro, the regional government for greater Portland, extending its reach to residents of various ages, abilities, and backgrounds. Through di...
    Show more

    Security Incidents

    Oregon Zoo Breach of Jun 2024
    Severity Score
    Significant to High

    Type

    Malware Attack

    Summary

    On June 26, 2024, Oregon Zoo discovered a cybersecurity incident involving its online ticketing service, leading to the theft of payment card information from approximately 118,000 individuals. The breach affected transactions from December 20, 2023, to June 26, 2024. Names, payment card numbers, CVVs, and expiration dates were exfiltrated due to threat actors redirecting transactions from their third-party vendor.

    In response, the affected website was decommissioned, and a new secure site was implemented. Oregon Zoo notified federal law enforcement and sent written notifications to those imp...
    Show more

    Severity

    The cyber incident on June 26, 2024, at Oregon Zoo resulted in a significant data breach, compromising their online ticketing service and affecting approximately 118,000 individuals. Sensitive payment card information, including names, card numbers, CVVs, and expiration dates, was stolen due to a web skimmer infection. Despite prompt actions such as taking the website offline, notifying law enforcement, and offering credit monitoring services, the scale and nature of the incident underscore a "Significant to High" severity level, with clear implications for both customer security and future pr...
    Show more

    Impact

    The cyber incident on June 26, 2024, led to a significant data breach at Oregon Zoo, compromising their online ticketing service. The breach involved the theft of sensitive payment card information from around 118,000 individuals who made transactions between December 20, 2023, and June 26, 2024. Customer data including names, payment card numbers, CVVs, and expiration dates were exfiltrated due to a web skimmer infection that redirected transactions from their third-party vendor.

    As a countermeasure, Oregon Zoo took the impacted website offline and replaced it with a new secure site. They pr...
    Show more