The UPS Store, Inc.
bd_2817665ef214de71 · schema v1 · pii pii-v1
Full breach record for The UPS Store, Inc. →5 incidents on fileThe UPS Store, Inc. discovered malware at 51 of its 4,470 franchised center locations across 24 states following a government bulletin about a broad-based malware intrusion targeting U.S. retailers. The malware was present between January 20 and August 11, 2014, potentially exposing customer names, postal addresses, email addresses, payment card information, and — for MailBox Manager account holders — Social Security numbers and driver's license numbers. Franchise owner login credentials were also potentially exposed. The company retained an IT security firm, implemented system enhancements and antivirus updates, and arranged free identity protection and credit monitoring through AllClear ID.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 20, 2014
Begins
Aug 20, 2014
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.