Sears Holdings Corporation
bd_6ccd597659c183d3 · schema v1 · pii pii-v1
Full breach record for Sears Holdings Corporation →3 incidents on fileSears Holdings notified South Carolina AG that a third-party vendor incorporating a malicious script into Sears.com/Kmart.com code collected names, addresses, and payment card info from customers who placed online orders between Sept 27 and Oct 12, 2017. Vendor notified Sears in mid-March 2018. Sears notified card companies, investigated, and cooperated with law enforcement.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 27, 2017
Begins
Mar 1, 2018
Discovered
May 18, 2018
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Oregon State AGbd_34500406ffb3c68c2018-05-17 · +1dVerified
- Montana State AGbd_e91e1c561709d7b72018-04-25 · +23dVerified
- Washington State AGbd_4127990c5317e1c82018-04-24 · +24dCandidate
- New Hampshire State AGbd_542e3870138514372018-04-24 · +24dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Apr 24 (WA), last May 18 (SC) — a 24-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.