First Data Corporation notified the California AG on May 7, 2012, regarding an administrative oversight where limited personal information (names, addresses, SSNs) of approximately 108,500 merchants was shared with three third-party firms (including a First Data subsidiary and a fraud analytics company) for testing credit and risk scoring products. The incident occurred between January and February 2012. The data was sent from application databases, not live transaction data, and no PCI data was impacted. The third parties deleted the data upon request, and First Data sent written notifications to the affected merchants.
Affected (this filing): 108,500