MalwareSkimmerData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Service Systems Associates, Inc.
bd_a83cea037edfa580 · schema v1 · pii pii-v1
Full breach record for Service Systems Associates, Inc. →Service Systems Associates, Inc. (SSA) experienced a data security breach between March 24 and May 20, 2015, affecting point-of-sale systems in gift shops at several zoo locations. Malware on the POS systems compromised payment card data, including names and credit card numbers. SSA engaged forensic investigators, removed the malware, and notified credit card companies. Affected individuals were offered one year of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3f2374047b0151ffMontana State AGfiled 2015-10-13Candidate
- bd_770b94243422682aWashington State AGfiled 2015-10-13Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-58264
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 13, 2015
- Raw hash
- 81928bcf2bc5275d2507925ffdbe11f5c19503cf7942b21f63c2c26f650bcb7a
Reporting entity
- Name
- Service Systems Associates, Inc.norm: service systems associates
Victim entity
- Name
- Service Systems Associates, Inc.norm: service systems associates
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Oct 13, 2015
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Working with law enforcement officials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.