Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICLowContained
The UPS Store, Inc.
bd_ca9a5f83bebc3884 · schema v1 · pii pii-v1
Full breach record for The UPS Store, Inc. →The UPS Store, Inc. reported a phishing incident affecting local store email accounts between September 29, 2020, and January 13, 2020. Unauthorized access was gained to a limited number of accounts containing customer documents with personal information (names, addresses). The company engaged a third-party cybersecurity firm, notified law enforcement, and offered 24 months of credit monitoring. No misuse was known at the time of filing.
California clockDiscovered Dec 23, 2019 → Notified Jan 21, 202029d ✓ CA 60-day OK28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_653c36227ae5d019Montana State AGfiled 2020-01-20Candidate
- bd_981cfae047a0fc7bWashington State AGfiled 2020-01-20Verified
- bd_d0346a89ea554cf2California State AGfiled 2019-11-27(54d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-186206
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 20, 2020
- Raw hash
- 6931a8ae0ba4ba505e55d4c0d3f8dd176f29c65206a77e577ed7513ef56ac4b5
Reporting entity
- Name
- The UPS Store, Inc.norm: the ups store
- Domain
- theupsstore.com
Victim entity
- Name
- The UPS Store, Inc.norm: the ups store
- Domain
- theupsstore.com
Incident
- Discovered
- Dec 23, 2019
- Materiality determined
- —
- Notification sent
- Jan 21, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 23, 2019→ Notified: Jan 21, 202029d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.