Hy-Vee
bd_c731de1bf1b228c0 · schema v1 · pii pii-v1
Full breach record for Hy-Vee →2 incidents on fileHy-Vee, Inc. notified the New Hampshire Attorney General of a security incident involving malware on POS devices at fuel pumps and restaurants. The malware accessed payment card track data (card numbers, expiration dates) from November 2018 through July 2019. The breach affected 8 New Hampshire residents. Hy-Vee engaged cybersecurity firms, notified law enforcement and card networks, removed the malware, and implemented enhanced security measures.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 9, 2018
Begins
Jul 29, 2019
Discovered
Nov 4, 2019
Filed
vs. sector median
+6 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_3b686b8c65b2794b2019-10-31 · +4dCandidate
- Massachusetts State AGbd_cfb01c30c54b10592019-10-31 · +4dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.