HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Jimmy John's
bd_dd63edfcd13e91ec · schema v1 · pii pii-v1
Full breach record for Jimmy John's →Jimmy John's Franchises LLC reported a security incident where an intruder stole log-in credentials from a point-of-sale vendor. The attacker used these credentials to remotely access POS systems at approximately 216 corporate and franchised locations between June 16, 2014, and September 5, 2014. Compromised data included credit/debit card numbers, cardholder names, verification codes, and expiration dates. The incident was contained, and the company hired forensic experts and offered identity protection services.
California clockDiscovered Jul 30, 2014 → Notified Sep 24, 201456d ✓ CA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-46686
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 24, 2014
- Raw hash
- 3de8e4dc93e7e3d0427655ac0ace248c2c465c91bfc025e588ea53eb11503ef2
Reporting entity
- Name
- Jimmy John'snorm: jimmy john s
- Domain
- jimmyjohns.com
Victim entity
- Name
- Jimmy John'snorm: jimmy john s
- Domain
- jimmyjohns.com
Incident
- Discovered
- Jul 30, 2014
- Materiality determined
- Sep 24, 2014
- Notification sent
- Sep 24, 2014
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 56d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 30, 2014→ Notified: Sep 24, 201456d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.