ShopRunner, Inc
bd_43894724582d6f68 · schema v1 · pii pii-v1
Full breach record for ShopRunner, Inc →ShopRunner, Inc. disclosed that credit/debit card info, names, and addresses of users adding payment info via Express Checkout were appended to retailer URL logs due to a misconfiguration. Data was encrypted in transit but captured in plain text by retailers/vendors. No improper use believed. ShopRunner scrubbed logs, deployed a fix, and offered 2 years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Dec 12, 2019
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_ecf5001bed7a8ed32019-12-13 · +1dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.