MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedRansom DemandedFINANCIAL_ACCOUNTPIILowContained
WAWA, INC.
bd_a570021cb784d84d · schema v1 · pii pii-v1
Full breach record for WAWA, INC. →Wawa, Inc. disclosed a security breach involving malware on payment processing systems at its stores. The malware operated between March 4, 2019, and December 12, 2019, affecting payment card data (credit/debit numbers, expiration dates, cardholder names) at potentially all locations. Wawa discovered the malware on December 10, 2019, contained it by December 12, 2019, and notified law enforcement and payment card companies. No other personal information was accessed. Wawa offered one year of credit monitoring through Experian.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_39e3080c2f5ba509Montana State AGfiled 2019-12-19Candidate
- bd_41ddba7e66977434California State AGfiled 2019-12-19Verified
- bd_b7c61660b28b8547Oregon State AGfiled 2019-12-19Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/06/Wawa-__-AG-Notice-Form-12_19_2019-__DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2019
- Raw hash
- 369cb351198cb5c177c88ec6ab08a3ab4517fa02d4140cd2069e0d19ce9309d6
Reporting entity
- Name
- WAWA, INC.norm: wawa
- Domain
- wawa.com
Victim entity
- Name
- WAWA, INC.norm: wawa
- Domain
- wawa.com
Incident
- Discovered
- Dec 10, 2019
- Materiality determined
- —
- Notification sent
- Dec 19, 2019
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.