DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedPIIIdentity (basic)LowContained

Yesway

bd_ad4e168bdab03521 · schema v1 · pii pii-v1

Severity

Low

Discovered

Nov 30, 2023

Filed

Jan 24, 2024

To disclose

8 weeks

Affected

1state residents only

Linked

4 filings

Confidence

67%
Full breach record for Yesway →2 incidents on file

Yesway notified the NH AG of a third-party breach involving Paycor's MOVEit file transfer program. An unauthorized person exploited a vulnerability to access files containing PII of one NH resident. Yesway mailed notification on Jan 24, 2024, and offered two years of identity theft protection.

Incident timeline

discovery → filing · 8 weeks / 55 days

Nov 30, 2023

Discovered

Jan 24, 2024

Filed

vs. sector median

1 wks faster

This filing is one of 4 filings about the same incident.View merged incident
Part of Paycor supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGJan 24 · first
Maine State AGJan 24 · first
New Hampshire State AGJan 24 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.