HackingStolen CredentialsData ExfiltratedPCIFINANCIAL_ACCOUNTLowResolved
Whole Foods Market Services, Inc.
bd_1ec8df54a4ca80f3 · schema v1 · pii pii-v1
Full breach record for Whole Foods Market Services, Inc. →Whole Foods Market Services, Inc. resolved a payment card data breach involving unauthorized access to POS systems at select venues. Unauthorized software copied card details (account numbers, expiration dates, verification codes) between March 10, 2017, and September 28, 2017. The incident was discovered on September 23, 2017, and resolved by October 20, 2017, after replacing affected POS systems and engaging forensic investigators.
California clockDiscovered Sep 23, 2017 → Notified Oct 20, 201727d ✓ CA 60-day OK27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0160e89d9c031a98Oregon State AGfiled 2017-10-20Candidate
- bd_d8e1dd783928230eWashington State AGfiled 2017-10-20Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-102871
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 20, 2017
- Raw hash
- e2e986cab92a50d430a23a73d348c2e22b60a22f66931657c3ef476ed25065f0
Reporting entity
- Name
- Whole Foods Market Services, Inc.norm: whole foods market
Victim entity
- Name
- Whole Foods Market Services, Inc.norm: whole foods market
Incident
- Discovered
- Sep 23, 2017
- Materiality determined
- —
- Notification sent
- Oct 20, 2017
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- contacted law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 27d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 23, 2017→ Notified: Oct 20, 201727d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.