COMPASS GROUP USA, INC.
bd_7df45cd8c4031749 · schema v1 · pii pii-v1
Full breach record for COMPASS GROUP USA, INC. →Compass Group USA, Inc. disclosed a security incident involving NEXTEP self-serve kiosks at three California locations. Unauthorized individuals installed malicious software to capture payment card data (account numbers, expiration dates, CVVs) between February 2 and March 9, 2015. The incident was contained, and affected users were offered one year of identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 2, 2015
Begins
Apr 27, 2015
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.