Deli Management, Inc.
ent_019ed9fde4e50e4e83e1b7f66cfd4f1b
Disclosures
11
State AG · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
3,400,000
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Deli Management, Inc.
- Normalized
- deli management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- RHWIM2PRW2QZDMC1HJ64
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- jasonsdeli.com
Disclosure history (11)newest first
- Massachusetts State AGas victim2024-02-15
Deli Management Inc. dba: Jason's reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-15. 1 Massachusetts residents were affected.
- South Carolina State AGas victim2024-01-22
Deli Management, Inc. d/b/a Jason's Deli notified customers of a data security incident discovered on December 21, 2023. Unauthorized parties used stolen login credentials (usernames/passwords) from other breaches to access customer accounts. Accessed data included names, addresses, phone numbers, birthdays, order history, and truncated gift card numbers. No full payment card numbers were stored or accessed. The company required more complex passwords and is restoring affected account balances.
- Maine State AGas victim2024-01-22
Deli Management, Inc. d/b/a Jason's Deli reported a credential stuffing incident on 12/21/2023 affecting 344,034 individuals. The breach exposed names and financial account numbers (including credit/debit card numbers with security codes/PINs). Written notification was sent on 01/19/2024. No identity theft protection services were offered. One Maine resident was affected.
- Indiana State AGas victim2024-01-19
Deli Management, Inc dba Jason's Deli reported a data breach to the Indiana Attorney General. 980 Indiana residents were affected. 344,034 individuals affected in total.
- Illinois State AGas victim2024-01-01
DELI MANAGEMENT DBA. JASON'S DELI filed a data-breach notice with the Illinois Attorney General in January 2024 (case 24-01-033). The register records the breach as discovered on December 21, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2018-05-23
Deli Management, Inc. dba Jason's Deli reported a supplemental data breach involving RAM-scraping malware on POS terminals. The incident occurred from June 8, 2017, to December 29, 2017, affecting approximately 3.4 million unique payment cards. The malware exfiltrated full track data including cardholder names and card numbers. The breach was discovered on December 22, 2017, and the company engaged forensic experts and law enforcement.
- South Carolina State AGas victim2018-01-16
Deli Management, Inc. d/b/a Jason's Deli disclosed an updated data breach notice filed in South Carolina. RAM-scraping malware was deployed on POS terminals from June 8, 2017, to December 29, 2017. Approximately 3.4 million unique payment cards were affected, with full track data (cardholder name, number, expiration, CVV) compromised. The breach was discovered on December 22, 2017, after payment processors detected data for sale on the dark web. The incident was contained, and forensic experts were engaged.
- California State AGas victim2018-01-11
Deli Management, Inc. (d/b/a Jason's Deli) experienced a data breach involving RAM-scraping malware deployed on POS terminals starting June 8, 2017. The company discovered the incident on December 22, 2017, when payment processors alerted them to card data for sale on the dark web. Approximately 2 million unique payment card numbers were impacted, including full track data (cardholder name, card number, expiration date, CVV). The breach was contained, and malware disabled. No California locations were affected, but California residents may have been impacted by visiting out-of-state locations.
- Washington State AGas victim2018-01-11
Deli Management, Inc. (Jason's Deli) filed a supplemental notice to the Washington AG regarding a RAM-scraping malware breach on POS terminals. The malware operated from June 8, 2017, to December 29, 2017. The updated investigation estimates approximately 3.4 million unique payment cards were affected, exposing full track data. The incident was discovered on December 22, 2017, and consumer notifications were sent on May 18, 2018.
- New Hampshire State AGas victim2018-01-11
Deli Management, Inc. dba Jason's Deli reported a data breach involving RAM-scraping malware on POS terminals starting June 8, 2017. Discovered Dec 22, 2017, the incident impacted approx. 2 million payment card numbers (full track data). The breach was contained and law enforcement notified.
- Oregon State AGas victim2018-01-11
Deli Management, Inc. (d/b/a Jason's Deli, Inc.) reported a data breach to the Oregon Attorney General. The breach was reported on 2018-01-11. The breach occurred during 6/8/2017. The breach was discovered on 12/22/2017. Notice was sent on 1/11/2018.