International Council of Shopping Centers
bd_c895ae6f0a795281 · schema v1 · pii pii-v1
Full breach record for International Council of Shopping Centers →ICSC notified NH AG of a security incident where unauthorized code was added to its checkout page (www.icsc.org) between March 24 and August 18, 2017. The code could capture names, addresses, payment card numbers, and CVVs. ICSC removed the code, engaged forensic experts, and notified payment card networks. 31 NH residents were affected. Notification sent September 15, 2017.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 24, 2017
Begins
Aug 18, 2017
Discovered
Sep 15, 2017
Filed
vs. sector median
15 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- California State AGbd_6913b34ada54a1ed2017-09-15Candidate
- Massachusetts State AGbd_a76a311cd2b791712017-09-15Verified
- New Hampshire State AGbd_0a4fd53a3f1a20992017-10-16 · +31dVerified
- Montana State AGbd_7e15966d354f5a2a2017-10-16 · +31dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Sep 15 (CA), last Oct 16 (MT) — a 31-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.