Westlake Touchless Car Wash
bd_43a4439765238110 · schema v1 · pii pii-v1
Westlake Touchless Car Wash experienced a data security incident involving its third-party point-of-sale system. Malware placed on the system by an intruder allowed access to payment card data (name, card number, security code) for customers who visited between February 6 and February 23, 2017. The company was informed of the intrusion on March 27, 2017. Malware was removed, and one year of credit monitoring is offered.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 6, 2017
Begins
Mar 27, 2017
Discovered
Apr 14, 2017
Filed
vs. sector median
5 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.