DisclosureLens
AccidentalFinancial ServicesTechnologyFinanceMisdeliveryCustomer Data InvolvedIdentity (basic)Government IDCriticalResolved

First Data Corporation

bd_7b7315e0b954f650 · schema v1 · pii pii-v1

Severity

Critical

Discovered

Apr 25, 2012

Filed

May 11, 2012

To disclose

16 days

Affected · nationwide

108,50015,399 in this filing

Linked

2 filings

Confidence

66%
Full breach record for First Data Corporation

First Data Corporation disclosed an administrative oversight where limited personal information (name, address, SSN) of approximately 108,500 merchants was shared with three third-party firms for testing verification and anti-fraud services in Jan-Feb 2012. First Data learned of the potential ambiguity in contract authorization on April 25, 2012. The data was deleted by the recipients at First Data's request. 15,399 California residents were affected.

California clockDiscovered Apr 25, 2012Notified May 7, 201212d CA 60-day OK16 days discovery → filing

Incident timeline

undetected · 115 days
discovery → filing · 16 days

Jan 1, 2012

Begins

Apr 25, 2012

Discovered

May 11, 2012

Filed

vs. sector median

6 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGMay 10 · first
California State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.