MalwareRansomwareData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
WAWA, INC.
bd_41ddba7e66977434 · schema v1 · pii pii-v1
Full breach record for WAWA, INC. →Wawa, Inc. disclosed a data security incident involving malware on payment processing servers at potentially all Wawa locations. The malware operated between March 4, 2019, and December 12, 2019, affecting payment card information (credit/debit numbers, expiration dates, cardholder names). Wawa engaged forensic investigators, notified law enforcement and payment card companies, contained the malware, and offered one year of free credit monitoring and identity theft protection to affected customers.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_39e3080c2f5ba509Montana State AGfiled 2019-12-19Candidate
- bd_a570021cb784d84dDelaware State AGfiled 2019-12-19Verified
- bd_b7c61660b28b8547Oregon State AGfiled 2019-12-19Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-185312
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2019
- Raw hash
- 46cdb57a108eec927445bac939e79dba4782ac24ed2add06475e24ebcfcda0cb
Reporting entity
- Name
- WAWA, INC.norm: wawa
- Domain
- wawa.com
Victim entity
- Name
- WAWA, INC.norm: wawa
- Domain
- wawa.com
Incident
- Discovered
- Dec 10, 2019
- Materiality determined
- Dec 19, 2019
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.