DisclosureLens
MalwareTechnologyRetail & ConsumerInformationStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFinancial accountFinancial credentialsMediumContained

Avanti Markets

bd_7bafe654a0a199d8 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 4, 2017

Filed

Aug 30, 2017

To disclose

8 weeks

Affected · nationwide

57,620454 in this filing

Linked

10 filings

Confidence

66%
Full breach record for Avanti Markets

Avanti Markets Inc. disclosed a malware attack affecting its self-service kiosks, originating from a third-party vendor's infected workstation. The incident, discovered on July 4, 2017, potentially compromised payment card data (card numbers, expiration dates, CVVs) for approximately 57,620 individuals nationwide, including 454 New Hampshire residents. The attack window spans from April 7, 2016, to August 4, 2017. Avanti implemented end-to-end encryption on all kiosks and offered two years of credit monitoring.

Incident timeline

undetected · 453 days
discovery → filing · 8 weeks / 57 days

Apr 7, 2016

Begins

Jul 4, 2017

Discovered

Aug 30, 2017

Filed

vs. sector median

11 wks faster

This filing is one of 10 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 37d gap

Filing propagation · 10 filings · 7 states

View merged incident ↗

Pattern: first filing Jul 24 (CA), last Oct 5 (NH) — a 73-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.