Penalty Amount
$8,000,000
Consumers Affected
34,000,000
Wawa Inc. agreed to pay $8 million to resolve a multistate investigation into a data breach that compromised approximately 34 million payment cards between April 2019 and December 2019. The breach involved malware that harvested card data from point-of-sale terminals. New Jersey will receive $2.5 million, and Wawa must implement enhanced cybersecurity measures including a comprehensive security program and third-party audits.
Wawa must pay a total of $8 million, with $2.5 million to New Jersey, establish a comprehensive information security program overseen by a credentialed expert, provide security training, comply with PCI DSS, and obtain a third-party compliance assessment within one year.
In-house legal teams should review vendor agreements, especially those involving payment processing or point-of-sale systems, for clauses on data security standards, PCI DSS compliance, and breach notification obligations. Customer agreements should be assessed for data handling and consent provisions related to payment card information. Employee agreements may need scrutiny for access controls and confidentiality terms. Key clauses to focus on include security requirements, audit rights, incident response procedures, and indemnification for data breaches. Changes might be necessary to enforce enhanced cybersecurity measures, mandate regular third-party audits, ensure encryption of payment data, and align breach notification timelines with settlement expectations.
Entity
Wawa Inc.
Also known as: Wawa
Industry
RetailOfficial Press Release
https://www.njoag.gov/acting-ag-platkin-co-leads-8-million-settlement-with-wawa-inc-over-data-breach-that-compromised-millions-of-payment-cards-in-new-jersey/
Wawa Inc
https://www.nj.gov/oag/newsreleases22/Wawa-Inc.pdf
New Jersey Attorney General Enforcement Page
https://www.njoag.gov/about/divisions-and-offices/division-of-consumer-affairs/
"Wawa Inc."
"$8 million"
"Wawa failed to employ reasonable information security measures to prevent such a data breach"
"compromised approximately 34 million payment cards"
$650K
The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.
On August 31, 2026, New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs joined the FTC and a bipartisan coalition of 21 other states in suing Amazon, alleging that for over seven years the company secretly rigged its advertising auctions—converting advertised 'second price' auctions into first-price auctions with hidden 'soft reserve price' surcharges—overcharging more than 500,000 small- and medium-sized businesses and extracting tens of billions of dollars. The complaint alleges Amazon actively concealed the surcharges, gave false and misleading answers to advertisers who asked directly about the auction format, and applied inflated upcharges on high-volume shopping days like Prime Day and Black Friday. The lawsuit was just filed; no penalties or remedies have been imposed yet.
A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.
A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.
Attorney General Jennifer Davenport joined a coalition of 17 attorneys general in sending comment letters to the Office of the Comptroller of the Currency and the Federal Reserve Board, urging them to deny OppFi's application to acquire BNC National Bank and obtain a national bank charter. The coalition argues that the charter would allow OppFi to circumvent state usury laws and offer high-cost loans with APRs up to 200%, harming consumers.
$400.0M
Attorney General Jennifer Davenport joined a coalition of 43 states and territories in announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations of widespread price-fixing and anticompetitive conduct in the generic drug market. Sandoz will pay approximately $469 million total including prior settlements, and has agreed to internal reforms to ensure fair competition.