HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Aptos, Inc. on behalf of Retailers in Attached Addenda
bd_0dcac7a565c128ed · schema v1 · pii pii-v1
Full breach record for Aptos, Inc. on behalf of Retailers in Attached Addenda →Aptos, Inc., a software platform provider, disclosed a breach affecting over 40 retailers using its eCommerce platform. Unauthorized actors accessed systems between February and December 2016, obtaining names, addresses, phone numbers, and payment card data. The incident was reported to the FBI and DOJ. Remediation included malware removal, security updates, and offering 12 months of credit monitoring to affected customers.
California clockDiscovered Nov 30, 2016 → Notified Feb 6, 201768d ✗ CA 60-day late15 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66878
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 13, 2017
- Raw hash
- 332bf89daa64cadee832725c4ae0ee107597eb1dba936b2f935ea0f76c094cbe
Reporting entity
- Name
- Aptos Networknorm: aptos network
- Domain
- aptosnetwork.com
Victim entity
- Name
- Aptos, Inc. on behalf of Retailers in Attached Addendanorm: aptos inc on behalf of retailers in attached addenda
Incident
- Discovered
- Nov 30, 2016
- Materiality determined
- —
- Notification sent
- Feb 6, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this matter to the FBI and the U.S. Department of Justice
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(103 days from discovery to filing)
- Compliance flags
- CA 60-day late · 68d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 30, 2016→ Notified: Feb 6, 201768d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.