Costco
ent_291c48fb6448f04da72b7e50
Disclosures
5
State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
29,425
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Costco
- Normalized
- costco— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- costco.com
Disclosure history (5)newest first
- Montana State AGas victim2017-07-10
Costco notified Montana employees that Sabre, a third-party travel booking provider, experienced a data breach between Aug 2016 and Mar 2017. Stolen credentials allowed access to encrypted hotel reservation data including names, addresses, payment card numbers, and potentially security codes. Costco discovered the breach in late June 2017 and offered identity theft protection services.
- Massachusetts State AGas victim2017-07-10
Costco reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-10. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2015-09-25
Costco reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-09-25. 2,592 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2015-09-22
Costco Photo Center experienced a security compromise via its hosting provider. An unauthorized party accessed the host system from June 19, 2014, to July 15, 2015, deploying malware that captured user input. Costco notified approximately 198 New Hampshire residents whose credit card info, names, addresses, emails, and passwords may have been compromised. Costco engaged forensic investigators, took the site offline, deleted stored card data, and provided credit monitoring services.
- Washington State AGas victim2015-09-22
Costco notified Washington AG of a security compromise at its online Photo Center host. An unauthorized party accessed the host system from June 19, 2014, to July 15, 2015, deploying malware that captured user input. Costco discovered the incident on July 17, 2015, when the host disabled payment processing. Approximately 29,425 Washington residents were notified. Compromised data included credit card details, names, addresses, emails, and passwords. Costco took the site offline, engaged forensic investigators, deleted stored card data, and offered credit monitoring.