Skip to content

Filters Fast

Disclosed Aug 14, 20206 years ago323,000 affectedSettled

Official notice

Checkout skimmer ran for nearly a year, hitting 320,000 customers; USD 200,000 NY AG

Attackers skimmed card data from Filters Fast's online checkout for purchases between July 16, 2019 and July 10, 2020, affecting about 320,000 consumers. The retailer paid New York USD 200,000.

What is known

People affected323,000 (as reported by the organization)
DisclosedAug 14, 2020
DiscoveredJul 20, 2020
HappenedJul 19, 2019
AttackHacking
Data exposedNames, Credentials and tokens, Payment cards, Addresses, Financial
SectorRetail · US
StatusSettled
Lawsuit or fineUSD 200,000 NY AG agreement (May 2021) (about $200K)

Sources

Source
California Attorney General breach notice: Filters Fastoag.ca.gov · Official notice
Washington Attorney General breach notice: Filters Fastatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: Filters Fastattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: Filters Fastjustice.oregon.gov · Official notice
NY AG: Agreement with Filters Fast after 2019 data breachag.ny.gov · Regulator
Indiana Attorney General 2020 data breach report: Filters Fastin.gov · Official notice
Maine Attorney General breach notice archive: Filters Fastmaine.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAAug 14, 2020
Washington AGresidents of WAAug 14, 20206,584
Oregon DOJresidents of ORAug 14, 2020323,000
Indiana AGresidents of INAug 14, 20207,050
Maine AGresidents of MEAug 14, 20201,177
Delaware DOJresidents of DEAug 27, 20201,492
ResearchtotalMay 18, 2021320,000
History of this record
  • 2026-09-25 · data_types: ["names","credentials","payment-card","addresses"] to ["names","credentials","payment-card","addresses","financial"] · backfill source
  • 2026-09-25 · records: 320000 to 323000 · backfill source
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · fine_usd: empty to 200000 · seed source
  • 2026-09-25 · lawsuit: empty to USD 200,000 NY AG agreement (May 2021) · seed source
  • 2026-09-25 · sector: other to retail · seed source
  • 2026-09-25 · data_types: ["names","credentials"] to ["names","credentials","payment-card","addresses"] · seed source
  • 2026-09-25 · records: 323000 to 320000 · seed source
  • 2026-09-25 · summary: empty to Attackers skimmed card data from Filters Fast's online checkout for purchases between July 16, 2019 and July 10, 2020, affecting about 320,000 consumers. The retailer paid New York USD 200,000. · seed source
  • 2026-09-25 · title: empty to Checkout skimmer ran for nearly a year, hitting 320,000 customers; USD 200,000 NY AG · seed source
  • 2026-09-25 · data_types: [] to ["names","credentials"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 323000 · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2020-07-20 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Filters Fast

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.