American Payroll Association
ent_33157e70ee5b095e1f08b339
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
548
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- American Payroll Association
- Normalized
- american payroll— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Montana State AGas victim2020-09-01
American Payroll Association (APA) disclosed a skimming cyberattack discovered on July 13, 2020. Unauthorized individuals installed a skimmer on APA's login and checkout pages via a CMS vulnerability, accessing credentials, payment card data, and PII starting May 13, 2020. APA patched the CMS, installed antivirus, reset passwords, and offered credit monitoring.
- New Hampshire State AGas victim2020-09-01
American Payroll Association notified NH AG of a skimming attack on its website's login and checkout pages. Unauthorized access occurred starting May 13, 2020, discovered around July 13, 2020. 37 NH residents affected; data included login credentials, payment card info, and PII. APA patched CMS, installed antivirus, increased patch frequency, and mandated password resets. Offered 12 months credit monitoring.
- Washington State AGas victim2020-08-19
American Payroll Association (APA) reported a skimming cyberattack in Washington state affecting 548 residents. Unauthorized individuals exploited a vulnerability in APA's CMS to install a skimmer on login and checkout pages. The incident occurred between May 13 and July 16, 2020. Data accessed included usernames, passwords, credit card info, and PII. APA patched the CMS, reset passwords, and offered credit monitoring.
- Illinois State AGas victim2020-01-01
AMERICAN PAYROLL ASSOCIATION filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-316). The register records the breach as discovered on July 13, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.