Staples, Inc.
ent_829dbd0f385acefa
Disclosures
6
Leak Site · State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3
as filed · State AG MA
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Staples, Inc.
- Normalized
- staples— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- XQM2JINI1UL7642TU573
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- staples.com
Disclosure history (6)newest first
- GLOBALLeak Siteas victim2023-12-09
Staples, Inc. is an American office retail company primarily involved in the sale of office supplies and related products through retail channels and business-to-business (B2B) oriented delivery operations. Its offerings include promo products, IT consulting, office furniture, printing services, and more. Its headquarters are located in Framingham, Massachusetts.
- GLOBALLeak Siteas victim2023-12-09
retail
- Massachusetts State AGas victim2016-07-14
Staples, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-07-14. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2016-02-29
Staples reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-02-29. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2014-12-19
Staples, Inc. notified the NH AG of malware detected on POS systems in mid-Sept 2014. Unauthorized access to payment card data (names, numbers, CVVs) occurred between July 20 and Sept 16, 2014. No NH stores affected. Total affected count unknown. Staples eradicated malware, engaged experts, and offered credit monitoring.
- California State AGas victim2014-12-19
Staples, Inc. notified the California Attorney General of a data security incident involving malware deployed to point-of-sale systems at 115 U.S. retail stores. The malware potentially allowed unauthorized access to payment card data, including cardholder names, payment card numbers, expiration dates, and card verification codes, for purchases made between July 20, 2014, and September 16, 2014. Staples eradicated the malware, enhanced security with new encryption tools, and offered one year of free identity protection services to affected customers.