Staples, Inc. notified California regulators of a data security incident involving malware deployed to point-of-sale systems at 115 U.S. retail stores. The malware potentially accessed payment card data (names, numbers, expiration dates, CVVs) for transactions between July 20, 2014, and September 16, 2014. Staples eradicated the malware, engaged outside experts, and enhanced POS security with new encryption. Free identity protection was offered to affected customers.