MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedTargetedPCIFINANCIAL_ACCOUNTHighContained
MICHAELS STORES, INC.
bd_a12900c0b9c4d4bd · schema v1 · pii pii-v1
Full breach record for MICHAELS STORES, INC. →Michaels Stores, Inc. reported a data security incident affecting approximately 3 million payment cards used at Michaels and Aaron Brothers stores between May 2013 and February 2014. Criminals used sophisticated malware on point-of-sale systems to capture payment card numbers and expiration dates. The incident is now fully contained. Michaels offered 12 months of free identity protection and credit monitoring to affected customers.
California clockDiscovered Jan 25, 2014 → Notified Apr 17, 201482d ✗ CA 60-day late2 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3,000,000 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-43887
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 27, 2014
- Raw hash
- 7206d83a084c29bbfd65ba8113de4a672668895f944c37ab817221348140b4ce
Reporting entity
- Name
- MICHAELS STORES, INC.norm: michaels stores
- Domain
- michaels.com
Victim entity
- Name
- MICHAELS STORES, INC.norm: michaels stores
- Domain
- michaels.com
Incident
- Discovered
- Jan 25, 2014
- Materiality determined
- —
- Notification sent
- Apr 17, 2014
- Affected individuals
- 3,000,000
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- CA 60-day late · 82d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 25, 2014→ Notified: Apr 17, 201482d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.