WAWA, INC.
bd_41ddba7e66977434 · schema v1 · pii pii-v1
Full breach record for WAWA, INC. →2 incidents on fileWawa, Inc. experienced a data security incident involving malware on payment processing servers. The malware affected customer payment card information (card numbers, expiration dates, names) at potentially all locations from March 4, 2019, to December 12, 2019. Malware was discovered on December 10, 2019, and contained by December 12, 2019. No PINs, CVVs, or driver's license info were affected. Wawa offered one year of identity theft protection and credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 4, 2019
Begins
Dec 10, 2019
Discovered
Dec 19, 2019
Filed
vs. sector median
6 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_39e3080c2f5ba5092019-12-19Candidate
- Massachusetts State AGbd_912dd3b3ba52e01b2019-12-19Verified
- Delaware State AGbd_a570021cb784d84d2019-12-19Verified
- Oregon State AGbd_b7c61660b28b85472019-12-19Verified by operator
Show 1 more filing ↓Show fewer ↑up to 4d gap
- South Carolina State AGbd_6b56a55be8d6f92e2019-12-23 · +4dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.