Costco
bd_ac6baa130a725d30 · schema v1 · pii pii-v1
Full breach record for Costco →2 incidents on fileCostco notified Washington AG of a security compromise at its online Photo Center host. An unauthorized party accessed the host system from June 19, 2014, to July 15, 2015, deploying malware that captured user input. Costco discovered the incident on July 17, 2015, when the host disabled payment processing. Approximately 29,425 Washington residents were notified. Compromised data included credit card details, names, addresses, emails, and passwords. Costco took the site offline, engaged forensic investigators, deleted stored card data, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 19, 2014
Begins
Jul 17, 2015
Discovered
Sep 22, 2015
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_5fe9eca8c784fcfe2015-09-22Candidate
- Massachusetts State AGbd_97a5559f454bed292015-09-25 · +3dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.