DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryFinancial accountFinancial credentialsIdentity (basic)LowContained

Pioneer Student

bd_edab483f2b106363 · schema v1 · pii pii-v2

Severity

Low

Discovered

Aug 10, 2026

Filed

Sep 3, 2026

To disclose

24 days

Affected · nationwide

6303 in this filing

Linked

2 filings

Confidence

69%

Pioneer Student discovered on August 10, 2026, that an unauthorized party exploited a vulnerability in a third-party checkout extension to gain access to its e-commerce website starting June 16, 2026. The attacker installed malicious code on the checkout page to capture payment card numbers, expiration dates, CVV codes, billing addresses, and email addresses. The code was active during two periods: June 18-July 22, 2026, and August 4-10, 2026. A total of 630 individuals nationwide, including 3 New Hampshire residents, were affected. Pioneer Student removed the code, patched the vulnerability, rotated credentials, and is offering 12 months of credit monitoring.

Incident timeline

undetected · 55 days
discovery → filing · 24 days

Jun 16, 2026

Begins

Aug 10, 2026

Discovered

Sep 3, 2026

Filed

vs. sector median

4 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AG+2d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.