DisclosureLens
AccidentalHealthcareProfessional ServicesHealthcareMisconfigurationCustomer Data InvolvedIdentity (basic)Government IDEducationMediumResolved

National Association of Chain Drug Stores Foundation

bd_fe33ee509c511a26 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 7, 2008

Filed

Nov 3, 2008

To disclose

27 days

Affected · nationwide

1603 in this filing

Linked

2 filings

Confidence

66%
Full breach record for National Association of Chain Drug Stores Foundation

The National Association of Chain Drug Stores Foundation experienced a data security breach on October 7, 2008, when its scholarship applicant database became publicly accessible via a link sent in an email to approximately 160 applicants. The link inadvertently permitted access to other applicants' files. The organization discovered the issue on October 7, 2008, and disabled the link and restored the database on October 8, 2008. Affected data included names, Social Security numbers, and permanent and school addresses. Three residents of New Hampshire were affected. Notification letters were mailed starting November 5, 2008.

Incident timeline

discovery → filing · 27 days

Oct 7, 2008

Begins

Oct 7, 2008

Discovered

Nov 3, 2008

Filed

vs. sector median

9 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGNov 3 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.