WAWA, INC.
ent_019e78e5b41c48e85222ec4cc4f95b26
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- WAWA, INC.
- Normalized
- wawa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300HUG8C5J4EYDF61
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- wawa.com
Disclosure history (7)newest first
- South Carolina State AGas victim2019-12-23
Wawa Inc. disclosed a data breach involving malware on payment processing servers affecting customer payment card information (card numbers, expiration dates, names) from March 4, 2019, to December 12, 2019. Wawa discovered the malware on December 10, 2019, and contained it by December 12. The company engaged forensic investigators, notified law enforcement, and offered one year of free credit monitoring and identity theft protection to affected customers.
- Montana State AGas victim2019-12-19
Wawa, Inc. disclosed a data breach involving malware on payment processing servers from March 4, 2019, to December 12, 2019. The incident compromised PCI data (card numbers, expiration dates, names) for customers using payment terminals. Wawa engaged forensic investigators, notified law enforcement, contained the malware, and offered credit monitoring.
- California State AGas victim2019-12-19
Wawa, Inc. experienced a data security incident involving malware on payment processing servers. The malware affected customer payment card information (card numbers, expiration dates, names) at potentially all locations from March 4, 2019, to December 12, 2019. Malware was discovered on December 10, 2019, and contained by December 12, 2019. No PINs, CVVs, or driver's license info were affected. Wawa offered one year of identity theft protection and credit monitoring.
- Massachusetts State AGas victim2019-12-19
Wawa, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-12-19. The report records the breach type as electronic.
- Delaware State AGas victim2019-12-19
Wawa, Inc. reported a security breach involving malware on payment processing systems affecting credit and debit card data. The malware was active from March 4, 2019, to December 12, 2019, and was discovered on December 10, 2019. Wawa contained the malware, notified law enforcement, and engaged forensic investigators. Affected individuals were offered one year of credit monitoring through Experian. The number of affected Delaware residents was not determined.
- Oregon State AGas victim2019-12-19
Wawa, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2019-12-19. The breach occurred during 3/4/2019 - 12/12/2019. The breach was discovered on 12/10/2019. 0 individuals were affected. Notice was sent on 12/19/2019.
- Illinois State AGas victim2019-01-01
WAWA, INC. filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-507). The register records the breach as discovered on March 4, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.