KURU Footwear
bd_6c0da7a3ba4744e9 · schema v1 · pii pii-v1
Full breach record for KURU Footwear →KURU Footwear disclosed a cyber-attack involving malware that potentially compromised credit and debit card data (cardholder name, address, card number, expiration date, CVV) for customers who transacted on www.kurufootwear.com between December 20, 2016, and March 3, 2017. The company discovered the breach on February 23, 2017, after investigating unusual activity reported by its credit card processor. Malware was removed, and the FBI is assisting in the investigation.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 20, 2016
Begins
Feb 23, 2017
Discovered
May 15, 2017
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_32d9a886f84b0f9a2017-05-15Verified
- Washington State AGbd_9876e32f13b75e3c2017-05-15Candidate
- Montana State AGbd_d5362188b1c65e2c2017-05-15Verified
- New Hampshire State AGbd_d874730a155f9ef12017-05-15Verified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.