DisclosureLens
MalwareRetail & ConsumerRetailInfostealerCapture App DataData ExfiltratedCustomer Data InvolvedMass DistributionMulti-Stage ChainIdentity (basic)Government IDFinancial accountCredentialsMediumResolved

The UPS Store, Inc.

bd_2817665ef214de71 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Aug 20, 2014

To disclose

Affected

Not disclosed

Confidence

75%
Full breach record for The UPS Store, Inc.5 incidents on file

The UPS Store, Inc. discovered malware at 51 of its 4,470 franchised center locations across 24 states following a government bulletin about a broad-based malware intrusion targeting U.S. retailers. The malware was present between January 20 and August 11, 2014, potentially exposing customer names, postal addresses, email addresses, payment card information, and — for MailBox Manager account holders — Social Security numbers and driver's license numbers. Franchise owner login credentials were also potentially exposed. The company retained an IT security firm, implemented system enhancements and antivirus updates, and arranged free identity protection and credit monitoring through AllClear ID.

Incident timeline

Jan 20, 2014

Begins

Aug 20, 2014

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.