← Blog

Heartland Payment Systems Data Breaches: Full Timeline Through 2026

Share on X

People search Heartland Payment Systems data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 7 Heartland Payment Systems-linked incidents, with headline counts up to 130M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Heartland Payment Systems breach history matters

Heartland Payment Systems operates in Finance (United States). Across indexed rows, recurring themes include zero-day exploitation and malware. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2018 — — Heartland Payment Systems: Information on this security breach is provided by…

Cataloged incident. Information on this security breach is provided by the Office of the Indiana Attorney General Exposed categories include Personal information. BreachHistory cites approximately 2K+ affected records in this row. See the heartland2018 and canonical BreachHistory entry.

2017 — — Heartland Payment Systems: Information on this security breach is provided by…

Cataloged incident. Information on this security breach is provided by the Office of the Indiana Attorney General Exposed categories include Personal information. BreachHistory cites approximately 55 affected records in this row. See the heartland2017 and canonical BreachHistory entry.

2015 — — Heartland Payment Systems: Location of breached information: Hacking/IT…

Cataloged incident. Location of breached information: Hacking/IT Incident Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 4K+ affected records in this row. See the heartland2015 and canonical BreachHistory entry.

2014 — — Heartland Payment Systems: Heartland Automotive (Jiffy Lube) has notified…

Cataloged incident. Heartland Automotive (Jiffy Lube) has notified customers of a data breach that has occured when one of their company owned laptop was stolen with personal information on it.The information included names, addresses, dates of birth, Social Security numbers.The company is offering 12 months free of AllClearID. For those affected call 1-877-437-4004. Exposed categories include Personal information. No attested victim count is published for this row yet. See the heartland2014 and canonical BreachHistory entry.

2012 — — Heartland Payment Systems: Location of breached information: Theft Business…

Cataloged incident. Location of breached information: Theft Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 1K+ affected records in this row. See the heartland2012 and canonical BreachHistory entry.

2009 — 130M

Cataloged incident. Largest payment card breach at the time. SQL injection; malware on payment systems. Exposed categories include Credit and debit card numbers. BreachHistory cites approximately 130M+ affected records in this row. See the heartland2009 and canonical BreachHistory entry.

2009 — 130M cards

Cataloged incident. Largest payment card breach at time. Albert Gonzalez prosecuted. $12.6M Visa fine. Exposed categories include Payment card numbers, expiration dates. BreachHistory cites approximately 130M+ affected records in this row. See the heartland-payment2009 and canonical BreachHistory entry.

Patterns and analysis

  • Zero-day exploitation and malware — appears across multiple Heartland Payment Systems catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the Heartland Payment Systems company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/heartland · Latest: heartland2018.

Sources: BreachHistory catalog (7 rows for Heartland Payment Systems), company and regulator disclosures cited in individual breach records.