The UPS Store, Inc.
bd_2817665ef214de71 · schema v1 · pii pii-v1
Full breach record for The UPS Store, Inc. →The UPS Store, Inc. discovered malware at 51 of its 4,470 franchised center locations across 24 states following a government bulletin about a broad-based malware intrusion targeting U.S. retailers. The malware was present between January 20 and August 11, 2014, potentially exposing customer names, postal addresses, email addresses, payment card information, and — for MailBox Manager account holders — Social Security numbers and driver's license numbers. Franchise owner login credentials were also potentially exposed. The company retained an IT security firm, implemented system enhancements and antivirus updates, and arranged free identity protection and credit monitoring through AllClear ID.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-46291
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 20, 2014
- Raw hash
- fc72664a5c61bcf246521b5330cd9bed8e376ad885684f73942b88e8b26b8336
Reporting entity
- Name
- The UPS Store, Inc.norm: the ups store
- Domain
- theupsstore.com
Victim entity
- Name
- The UPS Store, Inc.norm: the ups store
- Domain
- theupsstore.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 20, 2014
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1056 Input CaptureT1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.