MalwareRansomwareData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTPIILowContained
WestLake Laser Wash
bd_43a4439765238110 · schema v1 · pii pii-v1
Full breach record for WestLake Laser Wash →Westlake Touchless Car Wash (Daly City, CA) notified the California AG on April 14, 2017, of a POS system intrusion occurring Feb 6-23, 2017. A third-party provider's system was infected with malware, exposing customer payment card numbers, names, and security codes. The company removed the malware, engaged monitoring, and offered one year of credit monitoring via Kroll. No specific count of affected individuals was provided; a substitute notice was issued due to lack of customer contact info.
California clockDiscovered Mar 27, 2017 → Notified Apr 14, 201718d ✓ CA 60-day OK18 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-67633
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 14, 2017
- Raw hash
- b08c7ee35f2d6488b911e39d18e6b1b5e9bc889af42267f94bc3beba445da735
Reporting entity
- Name
- WestLake Laser Washnorm: westlake laser wash
- Domain
- westlakelaserwash.com
- Industry
- retail_consumer
Victim entity
- Name
- WestLake Laser Washnorm: westlake laser wash
- Domain
- westlakelaserwash.com
- Industry
- retail_consumer
Incident
- Discovered
- Mar 27, 2017
- Materiality determined
- —
- Notification sent
- Apr 14, 2017
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Third party
- via third-party platform provider
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 18d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 27, 2017→ Notified: Apr 14, 201718d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.