PowerStep
bd_35c55222e3d54d69 · schema v1 · pii pii-v1
PowerStep notified customers of unauthorized access to payment card data (names, contact info, card numbers, CVVs) from transactions between Sept 7 and Oct 4, 2021. Discovered Dec 8, 2021. Forensic investigators engaged; enhanced safeguards implemented.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 7, 2021
Begins
Dec 8, 2021
Discovered
Jan 7, 2022
Filed
vs. sector median
14 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Indiana State AGbd_0b39434ea3751ae32022-01-07Verified
- Maine State AGbd_2f67a7fc5d04160c2022-01-14 · +7dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jan 7 (IN), last Jan 14 (ME) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.