MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Epic Foods
bd_70c3f52753b7ae35 · schema v1 · pii pii-v1
Full breach record for Epic Foods →Epic Foods dba Bistro Burger (Market Street) reported a security incident at its San Francisco location where malicious software was installed on systems processing credit card transactions. The incident, occurring between Jan 4 and Mar 13, 2015, potentially compromised payment card data including names, account numbers, expiration dates, and security codes. The company contained the incident by replacing the targeted server and firewall.
California clockDiscovered Apr 16, 2015 → Notified Apr 16, 20150d ✓ CA 60-day OK5 days discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_85400f2a181b901fCalifornia State AGfiled 2015-03-09(43d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-52559
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2015
- Raw hash
- 1bf29af93d7a043a178dbd1b6342fe637d79b8ee86f1ae2c5cc8c27d3dc306f1
Reporting entity
- Name
- Epic Foodsnorm: epic foods
Victim entity
- Name
- Epic Foodsnorm: epic foods
Incident
- Discovered
- Apr 16, 2015
- Materiality determined
- —
- Notification sent
- Apr 16, 2015
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 16, 2015→ Notified: Apr 16, 20150d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.