DisclosureLens
HackingFinancial ServicesTechnologyFinanceStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Spark Pay Online Store

bd_2ee2223546ca62a5 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 6, 2017

Filed

Oct 16, 2017

To disclose

19 weeks

Affected

144state residents only

Linked

8 filings

Confidence

66%

Supplemental notice from Capital One regarding Spark Pay Online Store. Malicious code on merchant websites allowed unauthorized access to payment data between April 10 and June 7, 2017. Incident discovered June 6, 2017. 144 New Hampshire residents affected. FBI and card networks notified. Credit monitoring offered.

Incident timeline

undetected · 57 days
discovery → filing · 19 weeks / 132 days

Apr 10, 2017

Begins

Jun 6, 2017

Discovered

Oct 16, 2017

Filed

vs. sector median

+10 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 102d gap

Filing propagation · 8 filings · 6 states

View merged incident ↗
Montana State AGJul 6 · first
California State AGJul 6 · first
New Hampshire State AG+102d · this page

Pattern: first filing Jul 6 (NH), last Oct 17 (CA) — a 103-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.