First Data Corporation
bd_7b7315e0b954f650 · schema v1 · pii pii-v1
Full breach record for First Data Corporation →First Data Corporation notified the California AG on May 7, 2012, regarding an administrative oversight where limited personal information (names, addresses, SSNs) of approximately 108,500 merchants was shared with three third-party firms (including a First Data subsidiary and a fraud analytics company) for testing credit and risk scoring products. The incident occurred between January and February 2012. The data was sent from application databases, not live transaction data, and no PCI data was impacted. The third parties deleted the data upon request, and First Data sent written notifications to the affected merchants.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-23158
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 11, 2012
- Raw hash
- 6231c4591caf67980390c1bb6f2f1a085e6feaaa8bcc4283495faafb97d8d435
Reporting entity
- Name
- First Data Corporationnorm: first data
Victim entity
- Name
- First Data Corporationnorm: first data
Incident
- Discovered
- Apr 25, 2012
- Materiality determined
- May 7, 2012
- Notification sent
- —
- Affected individuals
- 108,500
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Initial access
- supply_chain
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.