DisclosureLens
MalwareTechnologyRetail & ConsumerInformationStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoverySupply Chain (3P Vendor)Identity (basic)Financial accountMediumContained

Aptos

bd_7b839a7a8a9f571c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 1, 2016

Filed

Feb 25, 2017

To disclose

17 weeks

Affected

10,000

Linked

6 filings

Confidence

64%
Full breach record for Aptos →

Aptos, Inc., a third-party e-commerce platform provider, experienced a malware intrusion between February and December 2016, discovered in November 2016. Attackers placed malware on Aptos servers, gaining access to customer payment card data (card numbers, expiration dates) and basic PII (name, address, phone, email) for approximately 10,000 clients, including Alpha Industries. Notification was delayed by law enforcement request. Aptos engaged forensic investigators, removed malware, and offered credit monitoring.

California clockDiscovered Nov 1, 2016 → Notified Feb 21, 2017112d ✗ CA 60-day late17 weeks discovery → filing

Incident timeline

undetected · 274 days
discovery → filing · 17 weeks / 116 days

Feb 1, 2016

Begins

Nov 1, 2016

Discovered

Feb 25, 2017

Filed

vs. sector median

+4 wks slower

This filing is one of 6 filings about the same incident.View merged incident
Part of Aptos supply-chain incident (2017) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filing ↓up to 27d gap

Filing propagation · 6 filings · 4 states

View merged incident ↗
New Hampshire State AGFeb 25 · first
California State AGFeb 25 · first · this page

Pattern: first filing Feb 25 (NH), last Mar 24 (OR) — a 27-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.