Staples, Inc.
bd_86c2f1aade967382 · schema v1 · pii pii-v1
Full breach record for Staples, Inc. →5 incidents on fileStaples, Inc. notified the California Attorney General of a data security incident involving malware deployed to point-of-sale systems at 115 U.S. retail stores. The malware potentially allowed unauthorized access to payment card data, including cardholder names, payment card numbers, expiration dates, and card verification codes, for purchases made between July 20, 2014, and September 16, 2014. Staples eradicated the malware, enhanced security with new encryption tools, and offered one year of free identity protection services to affected customers.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 20, 2014
Begins
Dec 19, 2014
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- New Hampshire State AGbd_3b23b3c8515a9da12014-12-19Verified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.