DisclosureLens
MalwareRetail & ConsumerHospitalityRetailRansomwareData ExfiltratedCustomer Data InvolvedFinancial accountIdentity (basic)PIIMediumContained

Service Systems Associates, Inc.

bd_770b94243422682a · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 18, 2015

Filed

Oct 13, 2015

To disclose

17 weeks

Affected

60,000

Linked

5 filings

Confidence

71%
Full breach record for Service Systems Associates, Inc.

Service Systems Associates, Inc. disclosed a malware breach affecting point-of-sale systems at gift shops in zoos and museums across six states. The incident, occurring March 24 to May 20, 2015, and discovered June 18, 2015, compromised credit card data for approximately 60,000 individuals. SSA engaged forensic investigators, notified the Secret Service and credit card companies, and offered credit monitoring.

Incident timeline

undetected · 86 days
discovery → filing · 17 weeks / 117 days

Mar 24, 2015

Begins

Jun 18, 2015

Discovered

Oct 13, 2015

Filed

vs. sector median

+9 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Montana State AGOct 13 · first
California State AGOct 13 · first
New Hampshire State AGOct 13 · first
Washington State AGOct 13 · first · this page

Pattern: first filing Oct 13 (MT), last Oct 19 (SC) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.