Pioneer Student
bd_edab483f2b106363 · schema v1 · pii pii-v2
Pioneer Student discovered on August 10, 2026, that an unauthorized party exploited a vulnerability in a third-party checkout extension to gain access to its e-commerce website starting June 16, 2026. The attacker installed malicious code on the checkout page to capture payment card numbers, expiration dates, CVV codes, billing addresses, and email addresses. The code was active during two periods: June 18-July 22, 2026, and August 4-10, 2026. A total of 630 individuals nationwide, including 3 New Hampshire residents, were affected. Pioneer Student removed the code, patched the vulnerability, rotated credentials, and is offering 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 16, 2026
Begins
Aug 10, 2026
Discovered
Sep 3, 2026
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_4bf3b342ffa9fac52026-09-01 · +2dCandidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.