CSIDB logo
Incident

Discover Financial Services

Incident posture

Attack window
Aug 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-28 00:00

Linked entities

Victim
Discover Financial Services
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Discover Financial Services experienced a data breach impacting cardholders' information, including account numbers, expiration dates, and security codes, though the incident did not originate from the company's own systems. The breach likely stemmed from compromised third-party entities or illicit card data sales, prompting the issuer to proactively replace affected cards with updated security features. Two distinct breach notifications suggested multiple sources of compromised data or differing card types involved, with variations in guidance for updating automatic billing and partial reissuance of new account numbers. The organization emphasized zero liability for unauthorized transactions but did not disclose the total number of impacted customers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 13, 2018, Discover Financial Services identified a potential compromise of customer payment card data, though the breach was not publicly disclosed until sample notifications were filed with the California Attorney General’s office on January 25, 2019. The incident did not involve Discover’s own systems, indicating that card information was likely obtained through third-party sources such as compromised merchant systems, skimming devices, or black market sales. Exposed data included account numbers, expiration dates, and security codes—sufficient details to enable fraudulent transactions. While California law mandated notification due to impacts on over 500 state residents, Discover did not disclose the total number of affected customers nationwide. The company initiated card replacements for all potentially compromised accounts, issuing new cards with updated expiration dates and security codes to mitigate fraud risks. Discover emphasized its zero-liability policy for unauthorized purchases in breach notifications sent to customers.

Two distinct sample notifications submitted to California authorities suggested variations in the breach’s scope or card types involved. One notification instructed customers to contact specific merchants managing automatic bill payments, while the other advised reaching out only to unlisted merchants. Additionally, only a subset of affected customers received cards with entirely new account numbers, implying differing risk assessments for portions of the exposed data. Discover confirmed ongoing monitoring of accounts and collaboration with third parties following external inquiries about the incident. The company reiterated that its internal systems remained secure throughout the event, shifting focus to external compromise vectors. No further technical details regarding attack methods, data exfiltration pathways, or identity of responsible parties were disclosed in available reports.

Sources

Sources available to members: 1 source.

CSIDB