DisclosureLens
PhysicalFinancial ServicesFinanceTheftCustomer Data InvolvedGovernment IDFinancial accountMediumContained

Heartland Payment Systems, Inc.

bd_73ead46a9a66e97a · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 8, 2015

Filed

May 28, 2015

To disclose

20 days

Affected

Not disclosed

Confidence

66%
Full breach record for Heartland Payment Systems, Inc.2 incidents on file

Heartland Payment Systems, Inc. reported the theft of password-protected computers from its Santa Ana, California office on February 22, 2015. The company became aware of the incident on May 8, 2015. The stolen devices may have contained Social Security numbers and bank account information for employees/customers. No evidence of data access was found. Heartland engaged law enforcement and provided one year of identity theft protection via Kroll.

Incident timeline

undetected · 75 days
discovery → filing · 20 days

Feb 22, 2015

Begins

May 8, 2015

Discovered

May 28, 2015

Filed

vs. sector median

5 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.