DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCapture Stored DataCustomer Data InvolvedTargetedIdentity (basic)Financial accountFinancial credentialsLowContained

THE TOPPS COMPANY, INC.

bd_583ab796c7eca5cc · schema v1 · pii pii-v1

Severity

Low

Discovered

Oct 12, 2016

Filed

Dec 27, 2016

To disclose

11 weeks

Affected

82state residents only

Linked

4 filings

Confidence

66%
Full breach record for THE TOPPS COMPANY, INC.2 incidents on file

The Topps Company, Inc. notified the NH Attorney General of a security breach discovered on Oct 12, 2016. Intruders accessed customer data (names, contact info, credit card details) for orders placed between July 30 and Oct 12, 2016. 82 NH residents affected. Notifications sent Dec 28, 2016. Topps engaged a security firm and provided one year of identity protection services.

Incident timeline

undetected · 74 days
discovery → filing · 11 weeks / 76 days

Jul 30, 2016

Begins

Oct 12, 2016

Discovered

Dec 27, 2016

Filed

vs. sector median

+3 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Massachusetts State AGDec 27 · first
California State AGDec 27 · first
Montana State AGDec 27 · first
New Hampshire State AGDec 27 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.