The UPS Store, Inc.
ent_23d86cf27bd9ffd4260be94f
Disclosures
15
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
17,094
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The UPS Store, Inc.
- Normalized
- the ups store— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- theupsstore.com
- Corporate parent
- UNITED PARCEL SERVICE, INC.— per SEC Exhibit 21 filing
Disclosure history (15)newest first
- Massachusetts State AGas victim2024-02-05
The UPS Store, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-05. 15 Massachusetts residents were affected.
- New Hampshire State AGas victim2020-01-24
The UPS Store reported a phishing incident affecting local store email accounts between Sept 29, 2019 and Jan 13, 2020. Approximately 13 New Hampshire residents were identified as affected. Personal information in documents emailed for printing was accessed. The company engaged forensic investigators, updated safeguards, notified law enforcement, and offered 24 months of credit monitoring.
- Indiana State AGas victim2020-01-21
The UPS Store, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2019-09-29 and was reported on 2020-01-21. 300 Indiana residents were affected. 17,094 individuals affected in total.
- Massachusetts State AGas victim2020-01-20
The UPS Store, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-01-20. 115 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2020-01-20
The UPS Store, Inc. notified Montana and Rhode Island residents of a phishing incident affecting local store email accounts between Sept 29, 2020, and Jan 13, 2020. The incident was discovered on Dec 23, 2019. Personal information (names) in documents emailed to stores was potentially accessed. No misuse was known. The company engaged forensic investigators, notified law enforcement, and offered 24 months of credit monitoring.
- Washington State AGas victim2020-01-20
The UPS Store, Inc. filed a supplemental notice with the Washington Attorney General regarding a phishing incident affecting local store email accounts. The breach, occurring between September 29, 2019, and January 13, 2020, exposed personal information (names, addresses) of 963 Washington residents. The company engaged forensic investigators, notified law enforcement, and offered 24 months of credit monitoring.
- California State AGas victim2020-01-20
The UPS Store, Inc. disclosed a phishing incident affecting local store email accounts between September 29, 2019, and January 13, 2020. An unauthorized person accessed a limited number of accounts, potentially viewing personal information contained in documents emailed for printing services. The company discovered the incident on December 23, 2019, engaged a third-party cybersecurity firm, notified law enforcement, and updated security safeguards. Affected individuals were offered 24 months of complimentary identity monitoring.
- Illinois State AGas victim2020-01-01
THE UPS STORE filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-071). The register records the breach as discovered on September 29, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2019-12-02
The UPS Store, Inc. notified the NH AG of a phishing incident affecting local store email accounts between Oct 11-22, 2019. Approx 3 NH residents' PII (name, SSN/gov ID) in documents emailed for printing was accessed. The UPS Store engaged forensic counsel, enhanced safeguards, and offered 24 months credit monitoring.
- Massachusetts State AGas victim2019-11-27
The UPS Store, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-11-27. 87 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2019-11-27
The UPS Store, Inc. reported a phishing incident occurring between October 11 and 22, 2019, where unauthorized persons accessed local store email accounts. Personal information, including names and potentially other data contained in documents emailed for printing services, was exposed. The company engaged a third-party cybersecurity firm, notified law enforcement, and offered 24 months of identity monitoring to affected individuals.
- Montana State AGas victim2019-11-27
The UPS Store, Inc. disclosed a phishing incident occurring Oct 11-22, 2019, affecting local store email accounts. Personal information (names, addresses) in documents emailed to stores for printing was potentially accessed. The company engaged forensic investigators, notified law enforcement, and offered 24-month credit monitoring. No specific count of affected individuals was provided in this Montana filing.
- Washington State AGas victim2019-11-26
The UPS Store, Inc. reported a phishing incident in Washington affecting 506 residents. Unauthorized access to local store email accounts occurred between Oct 11-22, 2019. Exposed data included names, SSNs, government IDs, and financial account info from documents emailed for printing. Notifications sent Nov 27, 2019.
- Massachusetts State AGas victim2014-10-02
UPS Store, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-10-02. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2014-08-20
The UPS Store, Inc. discovered malware at 51 of its 4,470 franchised center locations across 24 states following a government bulletin about a broad-based malware intrusion targeting U.S. retailers. The malware was present between January 20 and August 11, 2014, potentially exposing customer names, postal addresses, email addresses, payment card information, and — for MailBox Manager account holders — Social Security numbers and driver's license numbers. Franchise owner login credentials were also potentially exposed. The company retained an IT security firm, implemented system enhancements and antivirus updates, and arranged free identity protection and credit monitoring through AllClear ID.