HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
COMPASS GROUP USA, INC.
bd_7df45cd8c4031749 · schema v1 · pii pii-v1
Full breach record for COMPASS GROUP USA, INC. →Compass Group USA, Inc. disclosed a security incident involving malicious software installed on NEXTEP self-serve kiosks at select California dining locations. The malware captured payment card data (account numbers, CVV) from users between Feb 2 and Mar 9, 2015. Compass disabled payments, removed malware, and offered one year of credit monitoring. Incident is contained.
California clockDiscovered Mar 9, 2015 → Notified Apr 16, 201538d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-55656
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2015
- Raw hash
- d2e251f1c0ee3a683a24f91a89f7ba33049c4e6cad7f4c03e3cf0f762168b93d
Reporting entity
- Name
- COMPASS GROUP USA, INC.norm: compass group usa
- Domain
- compass-usa.com
Victim entity
- Name
- COMPASS GROUP USA, INC.norm: compass group usa
- Domain
- compass-usa.com
Incident
- Discovered
- Mar 9, 2015
- Materiality determined
- —
- Notification sent
- Apr 16, 2015
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Third party
- via NEXTEP
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 38d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 9, 2015→ Notified: Apr 16, 201538d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.