Hy-Vee
bd_3b686b8c65b2794b · schema v1 · pii pii-v1
Full breach record for Hy-Vee →2 incidents on fileHy-Vee, Inc. notified Montana of a malware incident affecting POS devices at fuel pumps, restaurants, and drive-thrus. Unauthorized access occurred between Nov 2018 and Aug 2019. Malware captured payment card track data. Hy-Vee engaged cybersecurity firms, notified law enforcement and card networks, and removed the malware. No specific individual count was provided in this notice.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 9, 2018
Begins
Jul 29, 2019
Discovered
Oct 31, 2019
Filed
vs. sector median
+6 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_cfb01c30c54b10592019-10-31Verified
- New Hampshire State AGbd_c731de1bf1b228c02019-11-04 · +4dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.