MalwareRansomwareData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTHighContained
Deli Management, Inc.
bd_0ec52a323ee32b9b · schema v1 · pii pii-v1
Full breach record for Deli Management, Inc. →Deli Management, Inc. (d/b/a Jason's Deli) disclosed a data security breach affecting approximately 2 million unique payment card numbers. Criminals deployed RAM-scraping malware on POS terminals starting June 8, 2017. The malware obtained full track data from magnetic stripes, including cardholder names, card numbers, expiration dates, and verification values. The breach was contained and the malware disabled. Jason's Deli engaged forensic experts and notified law enforcement.
California clockDiscovered Dec 22, 2017 → Notified Jan 11, 201820d ✓ CA 60-day OK20 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_49b1df9a42b8fc11Washington State AGfiled 2018-01-11Candidate
- bd_864fe98185e8613fOregon State AGfiled 2018-01-11Verified
- bd_7c535625e66137baSouth Carolina State AGfiled 2018-01-16(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-132606
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2018
- Raw hash
- b8f5cf34b71557e6da80d15069a99aa33ce16dec31aeceff3bc2b46e45199293
Reporting entity
- Name
- Deli Management, Inc.norm: deli management
- Domain
- jasonsdeli.com
Victim entity
- Name
- Deli Management, Inc.norm: deli management
- Domain
- jasonsdeli.com
Incident
- Discovered
- Dec 22, 2017
- Materiality determined
- —
- Notification sent
- Jan 11, 2018
- Affected individuals
- 2,000,000
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1498 Network Denial of ServiceT1530 Data from Cloud Storage Object
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney GeneralNotified federal law enforcement officials
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 20d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 22, 2017→ Notified: Jan 11, 201820d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.