DisclosureLens
HackingTransportation & LogisticsTransportationStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsMediumContained

Roberts Hawaii, Inc.

bd_66739fb592ffa41b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 5, 2017

Filed

Feb 24, 2017

To disclose

7 weeks

Affected

1,178state residents only

Linked

6 filings

Confidence

71%
Full breach record for Roberts Hawaii, Inc.

Roberts Hawaii notified the Washington AG of a cyberattack where unauthorized access to web servers allowed installation of code to copy customer checkout data (names, payment card numbers, CVVs) from July 2015 to Dec 2016. 1,178 WA residents affected. Incident contained; forensic firm engaged.

Incident timeline

undetected · 525 days
discovery → filing · 7 weeks / 50 days

Jul 30, 2015

Begins

Jan 5, 2017

Discovered

Feb 24, 2017

Filed

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filing

Filing propagation · 6 filings · 6 states

View merged incident ↗
Massachusetts State AGFeb 24 · first
California State AGFeb 24 · first
Oregon State AGFeb 24 · first
Montana State AGFeb 24 · first
New Hampshire State AGFeb 24 · first
Washington State AGFeb 24 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.