Costco
bd_5fe9eca8c784fcfe · schema v1 · pii pii-v1
Full breach record for Costco →2 incidents on fileCostco Photo Center experienced a security compromise via its hosting provider. An unauthorized party accessed the host system from June 19, 2014, to July 15, 2015, deploying malware that captured user input. Costco notified approximately 198 New Hampshire residents whose credit card info, names, addresses, emails, and passwords may have been compromised. Costco engaged forensic investigators, took the site offline, deleted stored card data, and provided credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 19, 2014
Begins
Jul 17, 2015
Discovered
Sep 22, 2015
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Washington State AGbd_ac6baa130a725d302015-09-22Verified
- Massachusetts State AGbd_97a5559f454bed292015-09-25 · +3dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.