Park'N Fly
bd_7144a72e29ab0475 · schema v1 · pii pii-v1
Full breach record for Park'N Fly →4 incidents on filePark ‘N Fly notified the NH Attorney General of a data security event involving its e-commerce website. In September 2014, the company noticed an escalation in fraud-related claims and engaged third-party forensics experts. The investigation confirmed the ecommerce site was infiltrated by an unauthorized third party, compromising payment card data (card number, name, billing address, expiration, CVV) and loyalty customer data (email, passwords, phone numbers). The compromise has been contained, but the investigation is ongoing. Park ‘N Fly began notifying the public via press release and website on January 13, 2015, and offered 12 months of identity monitoring. No specific count of affected individuals was disclosed.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 1, 2014
Discovered
Jan 20, 2015
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_1b081412af8a20872015-01-20Verified
- South Carolina State AGbd_408c80d823e386892015-01-20Verified
- California State AGbd_2cb24641f81286312015-01-13 · +7dCandidate
- New Hampshire State AGbd_02bdd2aa4b18807d2014-12-30 · +21dCandidate
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Dec 30 (NH), last Jan 20 (NH) — a 21-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.