DisclosureLens
MalwareRetail & ConsumerRetailData ExfiltratedCustomer Data InvolvedPCIFinancial accountFinancial credentialsIdentity (basic)LowContained

CM Ebar LLC

bd_620f3eae8dcbaad3 · schema v1 · pii pii-v1

Severity

Low

Discovered

Nov 3, 2015

Filed

Dec 10, 2015

To disclose

5 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for CM Ebar LLC

CM Ebar LLC (Elephant Bar) experienced a security incident involving malicious software installed on payment processing systems at multiple restaurant locations across seven states. The malware captured payment card information, including account numbers, expiration dates, and verification codes, for customers making purchases between August 12, 2015, and December 4, 2015. The incident was discovered on November 3, 2015, after the card processor alerted the company. The malware was disabled, systems were reconfigured, and law enforcement was notified. The incident is contained.

California clockDiscovered Nov 3, 2015Notified Dec 8, 201535d CA 60-day OK5 weeks discovery → filing

Incident timeline

undetected · 83 days
discovery → filing · 5 weeks / 37 days

Aug 12, 2015

Begins

Nov 3, 2015

Discovered

Dec 10, 2015

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.