DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Kmart discovers it was breached in September; discloses breach in SEC filing (UPDATED)

Posted on October 10, 2014 by Dissent

Danny Yadron of the Wall Street Journal just tweeted that Kmart has disclosed a data breach in its SEC filing. Indeed, they have:

On October 9, Kmart’s Information Technology team detected Kmart’s payment data systems had been breached and immediately launched a full investigation working with a leading IT security firm.

The investigation to date indicates the breach started in early September. According to the security experts Kmart has been working with, the Kmart store payment data systems were infected with a form of malware that was undetectable by current anti-virus systems. Kmart was able to quickly remove the malware. However, Kmart believes certain debit and credit card numbers have been compromised.

Based on the forensic investigation to date, no personal information, no debit card PIN numbers, no email addresses and no social security numbers were obtained by those criminally responsible. There is also no evidence that kmart.com customers were impacted.

Given the criminal nature of this attack, Kmart is working closely with federal law enforcement authorities, banking partners and IT security firms in this ongoing investigation. Kmart is deploying further advanced software to protect customers’ information.

Unlike JP Morgan which disclosed their breach on their site in a coordinated way with their SEC filing, Kmart does not appear to have posted anything on their web site yet.

UPDATE: Thanks to commenter Charlie, who points us to Kmart’s newly added statement on their site.

Related posts:

  • FBI Arrests Alabama Man in the January 2024 SEC X Hack that Spiked the Value of Bitcoin
Category: Business SectorMalwareOf NoteU.S.

Post navigation

← Travelers Says Liability Policy Doesn’t Cover P.F. Chang’s Data Breach
Colorado health officials announce privacy breach →

2 thoughts on “Kmart discovers it was breached in September; discloses breach in SEC filing (UPDATED)”

  1. Charlie says:
    October 10, 2014 at 7:04 pm

    Kmart statement on their website > http://www.kmart.com/en_us/dap/statement1010140.html?adcell=hpnewsrelease

    1. Dissent says:
      October 10, 2014 at 8:07 pm

      Thanks so much! Updated the post to link to their statement.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud
  • Swiss Health Foundation Radix Hit by Cyberattack Affecting Federal Data
  • Russian hackers get 7 and 5 years in prison for large-scale cyber attacks with ransomware, over 60 million euros in bitcoins seized
  • Bolton Walk-In Clinic patient data leak locked down (finally!)
  • 50 Customers of French Bank Hit by Insider SIM Swap Scam
  • Ontario health agency atHome ordered to inform 200,000 patients of March data breach
  • Fact-Checking Claims By Cybernews: The 16 Billion Record Data Breach That Wasn’t
  • Horizon Healthcare RCM discloses ransomware attack in December
  • Disgruntled IT Worker Jailed for Cyber Attack, Huddersfield
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.