MalwareRansomwareData ExfiltratedCustomer Data InvolvedTargetedFINANCIAL_ACCOUNTCREDENTIALSLowContained
Staples
bd_86c2f1aade967382 · schema v1 · pii pii-v1
Full breach record for Staples →Staples, Inc. notified California regulators of a data security incident involving malware deployed to point-of-sale systems at 115 U.S. retail stores. The malware potentially accessed payment card data (names, numbers, expiration dates, CVVs) for transactions between July 20, 2014, and September 16, 2014. Staples eradicated the malware, engaged outside experts, and enhanced POS security with new encryption. Free identity protection was offered to affected customers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-47797
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2014
- Raw hash
- 675811e9310160260f5a9e32f8ee1b4b2d3d52e5a81e80ed52905f27db2eab90
Reporting entity
- Name
- Staplesnorm: staples
- Domain
- staples.com
- Industry
- retail_consumer
Victim entity
- Name
- Staplesnorm: staples
- Domain
- staples.com
- Industry
- retail_consumer
Incident
- Discovered
- Sep 16, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- worked closely with ... law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(94 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.