MalwareRansomwareData EncryptedTargetedPCIFINANCIAL_ACCOUNTLowContained
Cici Enterprises, LP
bd_e92d6f0f92b7ed60 · schema v1 · pii pii-v1
Full breach record for Cici Enterprises, LP →CiCi Enterprises, LP reported a data breach impacting POS systems at certain restaurant locations. Malware was introduced by a hacker, compromising payment card information. The incident occurred between March 2015 and July 2016. The company retained a forensic firm, notified law enforcement and payment card networks, and remediated the threat.
California clockDiscovered Jul 19, 2016 → Notified Jul 19, 20160d ✓ CA 60-day OK≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a221bf92c125ab7dOregon State AGfiled 2016-07-20Verified by operator
- bd_10e69150d9e35ee7Washington State AGfiled 2016-07-19(1d gap)Candidate
- bd_7e11d4fb0a32f9a3Montana State AGfiled 2016-07-19(1d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-62944
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 20, 2016
- Raw hash
- 21b9ac4bb70dbdb5d0c53f006ac6f87a4da2fe0dbafcd9ed3dfd05edd0712c76
Reporting entity
- Name
- Cici Enterprises, LPnorm: cici enterprises
Victim entity
- Name
- Cici Enterprises, LPnorm: cici enterprises
Incident
- Discovered
- Jul 19, 2016
- Materiality determined
- —
- Notification sent
- Jul 19, 2016
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified state agencies as required by the laws of the jurisdictions in which our restaurants are located
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(1 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 19, 2016→ Notified: Jul 19, 20160d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.