Petco
ent_5b66b51294608adb
Disclosures
1
Leak Site · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Petco
- Normalized
- petco— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- petco.com
Unverified threat-actor claim — not a regulatory filing
Attribution, victim identity, and counts shown here derive from a threat actor's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Disclosure history (1)newest first
Subsidiary disclosures (8)filed by group companies
◈ These filings were made by or about subsidiaries of Petco — not by Petco itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia PupBox2020-10-02
PupBox, c/o Petco Animal Supplies Stores, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-10-02. 700 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGvia PupBox2020-10-02
PupBox, c/o Petco Animal Supplies Stores, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-10-02. The breach occurred during 2/11/2020 - 8/9/2020. The breach was discovered on 9/2/2020. 30,673 individuals were affected. Notice was sent on 10/2/2020.
- New Hampshire State AGvia PupBox2020-10-02
PupBox, a business unit of Petco, disclosed a security incident involving an unauthorized plugin on its website that captured and exfiltrated customer data (names, emails, addresses, credit card numbers, CVVs, and passwords) between February 11 and August 9, 2020. The incident was discovered on September 2, 2020, affecting approximately 30,673 individuals nationwide, including 145 New Hampshire residents. PupBox shut down impacted systems, engaged cybersecurity experts, and resolved the incident.
- Indiana State AGvia PupBox2020-10-02
PupBox, c/o Petco Animal Supplies Stores, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-02-11 and was reported on 2020-10-02. 546 Indiana residents were affected. 30,673 individuals affected in total.
- Montana State AGvia PupBox2020-10-02
PupBox, a business unit of Petco, disclosed a security incident where an unauthorized plugin on its website captured customer data (names, emails, credit card details, CVVs, passwords) between Feb 11 and Aug 9, 2020. The incident was discovered on Sept 2, 2020, affecting approximately 30,673 individuals. PupBox shut down systems and engaged cybersecurity experts.
- Washington State AGvia PupBox2020-10-02
PupBox, a business unit of Petco, notified the Washington AG of a security incident affecting 1,046 WA residents (approx. 30,673 total). An unauthorized plugin on the PupBox website captured personal and financial data (names, emails, credit card numbers, CVVs, passwords) between Feb 11 and Aug 9, 2020. PupBox detected the incident on Sept 2, 2020, engaged forensic investigators, removed the plugin, and reset user passwords.
- Maine State AGvia PupBox2020-10-02
PupBox, a subsidiary of Petco, reported an external system breach that compromised the financial account numbers or credit/debit card numbers of its customers. The incident occurred on February 11, 2020, and was discovered on September 2, 2020, affecting 176 Maine residents.
- California State AGvia PupBox2020-10-02
PupBox (a business unit of Petco Animal Supplies Stores, Inc.) disclosed a security incident affecting its website. An unauthorized plugin captured personal information, including names, emails, addresses, credit card numbers, expiration dates, CVVs, and passwords, between February 11, 2020, and August 9, 2020. The company became aware of the incident on September 2, 2020, after receiving notifications of fraudulent credit card activities. The incident has been resolved, and the company is implementing additional cybersecurity protections.