Score
| Primary URL | Location | Industry | score[.]org |
Country
United States of America
|
Retail
|
|---|
Profile
Score is an organisation headquartered in the United States of America that operates a website through which customers submit payment information for transactions. The entity’s online platform collects names, payment card account numbers, expiration dates and internal account identifiers as part of its commerce or service‑delivery process. While the precise nature of its products or services is not detailed in the available sources, the handling of payment data indicates involvement in electronic commerce or a similar transaction‑based business model. The organisation’s headquarters location situates it within the United States regulatory environment, particularly with respect to state data‑breach notification requirements.
On September 4 2014, Score experienced an unauthorized data breach that exposed customer payment information submitted via its website over a three‑month period. The compromised data included names, payment card account numbers, expiration dates and internal account identifiers, although there was no evidence that addresses or card security codes were accessed. The organisation did not detect the breach immediately; it became aware of the incident approximately seven weeks after it began. Upon discovery, Score launched an internal investigation and engaged external IT specialists to secure its payment systems and prevent further unauthorized access.
In response to the breach, Score undertook remediation efforts focused on restoring transactional security and rebuilding customer trust. The organisation notified affected individuals, advising them to monitor their financial statements for signs of fraud and providing information about obtaining credit monitoring and fraud alerts through national credit bureaus and federal agencies. Specific forensic findings from the investigation were not disclosed publicly, but the response emphasized securing the payment environment and mitigating potential harm to consumers. The incident was documented in California Attorney General breach notices, which are publicly accessible sources detailing the timeline and nature of the exposure.
