Spark Pay Online Store
ent_8c320512a853aaf92809b798
Disclosures
8
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,352
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Spark Pay Online Store
- Normalized
- spark pay capital one— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- California State AGas reporting2017-10-17
Spark Pay Online Store reported a data breach to the California Attorney General. The unauthorized access occurred between March 10, 2017, and April 10, 2017. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding data types, affected counts, or response actions are available in the text.
- New Hampshire State AGas reporting2017-10-16
Supplemental notice from Capital One regarding Spark Pay Online Store. Malicious code on merchant websites allowed unauthorized access to payment data between April 10 and June 7, 2017. Incident discovered June 6, 2017. 144 New Hampshire residents affected. FBI and card networks notified. Credit monitoring offered.
- Washington State AGas reporting2017-10-16
Spark Pay Online Store, a subsidiary of Capital One, disclosed a cyberattack involving malicious code on merchant websites. The incident, occurring between March 10 and June 7, 2017, and discovered on June 6, 2017, compromised payment card data and PII of 1,352 Washington residents. Capital One notified the FBI and provided credit monitoring.
- Oregon State AGas reporting2017-07-12
Spark Pay Online Store reported a data breach to the Oregon Attorney General. The breach was reported on 2017-07-12. The breach occurred during 4/10/2017 - 6/7/2017. The breach was discovered on 6/6/2017. Notice was sent on 6/15/2017.
- Massachusetts State AGas reporting2017-07-07
Spark Pay Online Store reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-07. 1,020 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas reporting2017-07-06
Spark Pay Online Store (a division of Capital One) notified the NH AG of a breach affecting 120 NH residents. Malicious code on merchant sites captured payment info (names, addresses, card numbers, CVVs) for transactions between April 10 and June 7, 2017. Discovered July 6, 2017. Sites were taken offline, code removed, and FBI/payment networks notified. Credit monitoring offered.
- Montana State AGas reporting2017-07-06
Spark Pay Online Store, a division of Capital One, N.A., notified customers of a security event involving malicious code on merchant websites that allowed fraudsters to obtain payment information. The incident affected transactions between April 10, 2017, and June 7, 2017. Data involved included names, addresses, phone numbers, emails, and full payment card details (number, expiration, CVV). Capital One engaged law enforcement, notified card networks, and provided two years of free credit monitoring.
- California State AGas reporting2017-07-06
Spark Pay Online Store, a division of Capital One, N.A., disclosed a security event involving malicious code on a merchant website hosted by Spark Pay. The code allowed fraudsters to obtain customer payment information, including name, address, phone number, email, payment card number, expiration date, and CVV, for transactions made between April 10, 2017, and June 7, 2017. The company removed the code, notified card networks and law enforcement, and offered two years of credit monitoring.