DisclosureLens
MalwareFinancial ServicesTechnologyFinanceRansomwareData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountMediumContained

Spark Pay Online Store

bd_31e20ffa8d1cc464 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 6, 2017

Filed

Oct 16, 2017

To disclose

19 weeks

Affected

1,352state residents only

Linked

8 filings

Confidence

69%

Spark Pay Online Store, a subsidiary of Capital One, disclosed a cyberattack involving malicious code on merchant websites. The incident, occurring between March 10 and June 7, 2017, and discovered on June 6, 2017, compromised payment card data and PII of 1,352 Washington residents. Capital One notified the FBI and provided credit monitoring.

Incident timeline

undetected · 88 days
discovery → filing · 19 weeks / 132 days

Mar 10, 2017

Begins

Jun 6, 2017

Discovered

Oct 16, 2017

Filed

vs. sector median

+10 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 102d gap

Filing propagation · 8 filings · 6 states

View merged incident ↗
Montana State AGJul 6 · first
California State AGJul 6 · first
Washington State AG+102d · this page

Pattern: first filing Jul 6 (NH), last Oct 17 (CA) — a 103-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.