MalwareRansomwareData EncryptedTargetedPCIFINANCIAL_ACCOUNTLowContained
Russell Stover Chocolates, LLC
bd_27344e2717462c00 · schema v1 · pii pii-v1
Full breach record for Russell Stover Chocolates, LLC →Russell Stover Chocolates, LLC notified consumers of a payment card security incident affecting retail stores. Malware on POS systems may have exposed card numbers, expiration dates, and names between Feb 9 and Aug 7, 2019. The company engaged forensic experts, contained the malware, and notified law enforcement. No evidence of misuse was found at the time of notice.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2019/RussellStover.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2019
- Raw hash
- ccc2429b27f9f5d511c8d2f7210c6090217fe5fa74ae9df5568573fa5f5c7525
Reporting entity
- Name
- Russell Stover Chocolates, LLCnorm: russell stover chocolates
Victim entity
- Name
- Russell Stover Chocolates, LLCnorm: russell stover chocolates
Incident
- Discovered
- Aug 30, 2019
- Materiality determined
- —
- Notification sent
- Aug 30, 2019
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1052 Exfiltration Over Physical Medium
- Threat actor
- ExternalFinancial
- Regulator citations
- notified the appropriate law enforcement and regulatory authorities
- Initial access
- external_remote_services
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.