October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Park ’N Fly Confirmed a 2015 Data Breach Affecting Online Reservation Customers

Park ’N Fly’s payment-card incident was disclosed in January 2015 and concerned online reservations made from November 27, 2013, through December 24, 2014. The company identified payment-card and loyalty data as potentially at risk, but did not disclose a victim count or detailed attack method.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Park ’N Fly disclosed a security compromise on January 13, 2015—not a new 2026 breach. The incident involved payment-card information used on the company’s e-commerce reservation website. A later update identified online reservations made from November 27, 2013, through December 24, 2014, as potentially affected.

What Park ’N Fly confirmed

In a notice filed with the California attorney general, Park ’N Fly said payment-card data processed through its e-commerce website could have been at risk. The company described the matter as a security compromise and said it had contained or addressed the issue while investigating its scope. The notice did not provide a technical description of the intrusion, identify an attacker, or establish that every potentially exposed record was taken.

The official disclosure is dated January 13, 2015. Recent breach-tracker pages can have newer crawl or update dates, but those dates do not turn this historical incident into a current breach. The state filing remains available at California’s breach-notice record.

Which reservations were in the potentially affected period?

Park ’N Fly’s later consumer update narrowed the relevant window to online reservations made between November 27, 2013, and December 24, 2014. That window concerns reservations made through the e-commerce website. It does not establish that every Park ’N Fly customer was affected or that payments made at physical parking facilities were included.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The date range is reported in the company update reproduced by DataBreaches.Net. A reservation during that period indicates possible exposure, not confirmed theft or fraudulent use.

What information may have been exposed?

Park ’N Fly identified two broad categories of information as potentially at risk:

Category Information identified in the notice What that means
Payment-card data Card number, cardholder name, billing address, expiration date and CVV code These elements were described as potentially at risk; the notice did not say every customer’s complete set of data was exposed.
Loyalty-account data Email address, Park ’N Fly password and telephone number The notice identified these fields as potentially exposed for loyalty customers, without confirming misuse or whether passwords were decrypted.

The disclosure does not establish that all listed fields were taken, that every card was copied, or that possession of a CVV led to fraudulent transactions. It also does not report exposure of Social Security numbers or identity-document numbers.

How the incident came to light

Contemporaneous reporting said banks noticed a pattern of fraudulent activity on a significant number of cards that had recently been used for online reservations at Park ’N Fly locations. That account provides investigative context, not a quantified company finding or a definitive explanation of how an intruder entered the system. KrebsOnSecurity’s report also discussed a separate OneStopParking.com incident; the two companies should not be treated as one breach or as evidence of a shared attacker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The available public notices do not state how many customers or records were affected. The Identity Theft Resource Center’s historical listing records the number as unknown: historical breach table.

What Park ’N Fly did in response

The company’s response unfolded across the January disclosure and a February update:

  • It engaged third-party data-forensics experts to investigate.
  • It said the compromise had been contained or addressed and that website security was enhanced.
  • It restored the reservations website.
  • It added a PayPal-hosted payment solution as part of the later remediation.
  • It established a toll-free customer call center.
  • It offered 12 months of identity monitoring and identity-protection services to potentially affected customers in 2015.
  • It said it was mailing notices to affected customers for whom it had current mailing addresses.

The PayPal-hosted payment change and website restoration belong to the later update, not necessarily the initial January announcement. The historical monitoring offer should not be assumed to be open for enrollment today.

What customers were told to do

Park ’N Fly’s 2015 notice advised potentially affected customers to:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Review payment-card and account statements for suspicious transactions.
  2. Contact the card issuer about the possible compromise and follow its instructions about replacement or monitoring.
  3. Check credit reports and remain alert for identity theft or financial fraud.
  4. Consider fraud alerts offered by the major credit bureaus.
  5. Use the company’s identity-monitoring and protection services if eligible under the 2015 offer.

The notice directed consumers to the federally authorized free-credit-report site, AnnualCreditReport.com. That address remains useful for checking reports, although any Park ’N Fly-specific monitoring benefit described in 2015 was time-limited.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a former customer can still do

If you used a card during the window

Search old statements or card-account records for online Park ’N Fly reservations between November 27, 2013, and December 24, 2014. If the card account is still open, ask the issuer whether it can review historical activity or provide replacement guidance. If the account was closed, contact the former issuer if records are still available.

If you reused a Park ’N Fly password

Change that password anywhere it was reused and enable multifactor authentication where available. This is a precaution based on the disclosed possibility that Park ’N Fly loyalty passwords were at risk; it is not evidence that those passwords were actually misused.

If you are concerned about identity fraud

Review all three credit reports, consider a fraud alert or credit freeze based on your circumstances, and investigate unfamiliar accounts or inquiries promptly. The public notice does not establish exposure of Social Security numbers, so stronger identity-protection measures should be considered according to your broader risk rather than assumed necessary solely because of this incident.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What remains unknown

  • The confirmed number of affected customers or records.
  • The malware, access method, attacker or exact period of unauthorized access.
  • Whether particular individuals’ data was actually exfiltrated.
  • Whether any specific identity theft or fraud was caused by the incident.
  • Any ransom demand, regulatory penalty, lawsuit outcome or settlement.

The reservation window spans more than a year, but that does not prove continuous unauthorized access throughout the entire period. Likewise, identifying CVV as potentially at risk does not prove that every card’s CVV was copied or used.

Current status

This is a historical 2015 e-commerce payment-card incident. It should not be reported as a newly disclosed 2026 Park ’N Fly breach. Readers verifying an old reservation should focus on the specified online-reservation dates, distinguish website transactions from physical-lot payments, and treat the former 12-month monitoring offer as expired unless they have separate documentation showing otherwise.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.