DisclosureLens
MalwareRetail & ConsumerTechnologyRetailCapture App DataCustomer Data InvolvedData ExfiltratedPCIIdentity (basic)Financial accountLowActive

Datapak Services

bd_89f1f4964aabfd61 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Nov 8, 2013

To disclose

Affected

Not disclosed

Linked

4 filings

Confidence

70%
Full breach record for Datapak Services2 incidents on file

Datapak Services Corporation, an order fulfillment and payment processor for e-commerce websites, discovered malware placed on its systems on March 5, 2013, potentially enabling unauthorized access to customer credit card information including name, address, primary account number, expiration date, and card security code. The investigation was ongoing at time of notification. Affected individuals were offered one year of identity protection services through AllClearID.

Incident timeline

Mar 5, 2013

Begins

Nov 8, 2013

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 3 states

View merged incident ↗
California State AG+37d · this page

Pattern: first filing Oct 2 (NH), last Nov 8 (CA) — a 37-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.