MICHAELS STORES, INC.
bd_a12900c0b9c4d4bd · schema v1 · pii pii-v1
Full breach record for MICHAELS STORES, INC. →Michaels Stores, Inc. confirmed that its U.S. point-of-sale systems and those of subsidiary Aaron Brothers were attacked by criminals using sophisticated malware between May 2013 and February 2014. Approximately 3 million payment cards (2.6 million Michaels, 400,000 Aaron Brothers) may have been impacted, exposing card numbers and expiration dates. The incident was contained by April 2014. The company offered 12 months of identity protection and credit monitoring to affected customers.
J jump to incidentP pin to compareR raw source
Incident timeline
May 8, 2013
Begins
Jan 25, 2014
Discovered
Jan 27, 2014
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- New Hampshire State AGbd_57e078010e175fe82014-04-18 · +81dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Jan 27 (CA), last Apr 18 (NH) — a 81-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.