Sears Holdings Corporation
bd_462527eb50757e67 · schema v1 · pii pii-v1
Full breach record for Sears Holdings Corporation →3 incidents on fileSears Holdings Management Corporation notified customers that a vendor providing online support services for Sears.com and Kmart.com experienced a security incident. An unauthorized individual incorporated a malicious script into the vendor's code, collecting personal information (name, address) and payment card information from customers who completed online orders between September 27, 2017, and October 12, 2017. Sears was informed of the incident in mid-March 2018. Payment card companies were notified, and an investigation was conducted. No evidence suggests Sears' internal systems were accessed.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 27, 2017
Begins
May 17, 2018
Filed
vs. sector median
+54 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.