DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsCredentialsMediumContained

National Wholesale Company, Inc.

bd_f8c5dce62a3629bf · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 14, 2016

Filed

Nov 3, 2016

To disclose

20 days

Affected

14,281

Linked

4 filings

Confidence

65%
Full breach record for National Wholesale Company, Inc.2 incidents on file

National Wholesale Incorporated disclosed that unknown individuals targeted its website (www.shopnational.com) and inserted harmful code to monitor customer input during online orders. The incident occurred between September 1 and October 15, 2016, and was discovered on October 14, 2016. Approximately 14,281 customers may have had their name, address, phone, email, payment card number, expiration date, CVV, and potentially username/password compromised. The company removed the malware, engaged IT security firms, and reported the incident to the FBI.

California clockDiscovered Oct 14, 2016Notified Nov 2, 201619d CA 60-day OK20 days discovery → filing

Incident timeline

undetected · 43 days
discovery → filing · 20 days

Sep 1, 2016

Begins

Oct 14, 2016

Discovered

Nov 3, 2016

Filed

vs. sector median

5 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Montana State AGNov 3 · first
California State AGNov 3 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.