Menu
Browse

Cyber Incident Victim: Mastercard Priceless Specials

Date:

Aug 2019

Location:

Germany

Summary

A data breach impacting Mastercard's Priceless Specials loyalty program exposed customers' personal information, including payment card numbers, names, dates of birth, gender, mailing addresses, email addresses, and telephone numbers. The compromised data was published online, prompting the company to suspend the German program, remove hosted information, and notify affected individuals while offering credit monitoring and identity theft prevention services. The incident originated from a third-party vendor managing the loyalty platform, with unauthorized data distributions occurring in multiple instances, though sensitive details like account passwords and card security codes remained unaffected. Authorities in Germany and Belgium were notified, and investigations are ongoing to address the breach.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On August 19, 2019, Mastercard discovered that customer data from its German Priceless Specials loyalty program had been published on the Internet. The exposed information included names, payment card numbers, email addresses, home addresses, phone numbers, gender, and dates of birth. Mastercard clarified that the breach was confined to the Specials program and did not involve Mastercard's payment network. The leaked payment card data consisted solely of card numbers, with no compromise of account passwords, card security codes, or expiration dates. Upon identifying the leak, Mastercard promptly suspended the German Priceless Specials platform and took its website offline, replacing it with a notice about the incident's isolation from core payment systems. The company initiated an investigation and requested removal of the exposed data from hosting sites.

Cyber Incident Image

Two days later on August 21, Mastercard became aware of a second file containing personal information published online and began efforts to remove it. The company notified German and Belgian Data Protection Authorities (DPAs), confirming the breach impacted personal identifiers (titles, names, birthdates, gender) and contact details (mailing addresses, emails, phone numbers) alongside card numbers. All affected customers were directly informed about the exposure. Mastercard offered complimentary credit monitoring and identity theft prevention services to impacted users. An August 23 update attributed the incident to a third-party vendor managing the German loyalty platform, which enabled unauthorized data distribution. The Belgian DPA chairman confirmed coordination with German authorities and Mastercard to gather additional details while addressing public concerns. No evidence suggested misuse of the exposed data at the time of reporting.

Sources
Sources available to members
1 source