Aptos
bd_d70604f71608d864 · schema v1 · pii pii-v1
Full breach record for Aptos →Aptos, Inc., an e-commerce platform provider, notified the New Hampshire Attorney General of a security incident involving malicious software (ransomware) on its systems. The intrusion occurred between February 2016 and December 2016, affecting customer demographic and payment card data (including CVV2) for 2,858 New Hampshire residents. Aptos reported the incident to the FBI and DOJ, engaged a cybersecurity firm to remove malware and strengthen access controls, and facilitated notification to affected retailers and consumers.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 1, 2016
Begins
Nov 1, 2016
Discovered
Mar 3, 2017
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_240674ed1319758d2017-02-27 · +4dVerified
- California State AGbd_3b0817bc12a5f5cb2017-02-27 · +4dVerified
- New Hampshire State AGbd_0ef30bb08f7149d82017-02-25 · +6dCandidate
- California State AGbd_7b839a7a8a9f571c2017-02-25 · +6dVerified
Show 1 more filing ↓Show fewer ↑up to 21d gap
- Oregon State AGbd_95597eac1553f5362017-03-24 · +21dCandidate
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Feb 25 (NH), last Mar 24 (OR) — a 27-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.