Whole Foods Market Services, Inc.
ent_2e28a3018be08f7646358f76
Disclosures
9
State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
169
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Whole Foods Market Services, Inc.
- Normalized
- whole foods market— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- New Hampshire State AGas victim2018-11-01
Whole Foods Market Group, Inc. notified the NH Attorney General that a company-issued laptop containing the name and bank account information of one New Hampshire resident was stolen from an employee's vehicle on August 3, 2018. The company engaged a forensic firm and determined the data was present. Remediation includes deploying encryption on laptops and reinforcing data handling practices.
- Massachusetts State AGas victim2018-10-31
Whole Foods Market Group Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-10-31. 25 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2017-10-20
Whole Foods Market Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-10-20. The breach occurred during 3/10/2017 - 9/28/2017. The breach was discovered on 9/23/2017. Notice was sent on 10/20/2017.
- California State AGas victim2017-10-20
Whole Foods Market resolved an incident involving unauthorized software on point-of-sale systems at certain tap rooms and full-service restaurants. The software copied payment card information (account number, expiration date, verification code, name) from March 10, 2017, to September 28, 2017. The company discovered the access on September 23, 2017, engaged forensic experts, contacted law enforcement, and replaced the affected POS systems.
- New Hampshire State AGas victim2017-10-20
Whole Foods Market Services, Inc. notified the NH Attorney General of unauthorized access to payment card data at select in-store venues (tap rooms/restaurants) via unauthorized POS software. Access occurred March 10–Sept 28, 2017; discovered Sept 23, 2017. POS systems replaced; law enforcement notified. Exact count of affected NH residents unknown due to lack of customer contact info; substitute notice posted online.
- Washington State AGas victim2017-10-20
Whole Foods Market Services, Inc. reported a malware incident affecting payment card data at select in-store venues (tap rooms/restaurants) from March 10 to September 28, 2017. Unauthorized software copied card info. The company engaged forensic investigators, contacted law enforcement, replaced POS systems, and resolved the incident. Affected count unknown due to lack of customer contact info.
- New Hampshire State AGas victim2017-08-22
TALX Corporation, a subsidiary of Equifax, filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access to Whole Foods Market employees' online payroll portal accounts. The incident involved unauthorized access between April 18, 2016, and July 17, 2017, affecting 4 New Hampshire residents. Data accessed included W-2 forms (SSN, earnings) and personal details. TALX notified law enforcement and the IRS, implemented enhanced fraud monitoring, and offered identity protection services.
- Massachusetts State AGas victim2017-06-20
Whole Foods Market Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-06-20. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2010-12-17
Whole Foods Market reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-12-17. 169 Massachusetts residents were affected. The report records the breach type as electronic.