Park ’N Fly disclosed a security compromise on January 13, 2015—not a new 2026 breach. The incident involved payment-card information used on the company’s e-commerce reservation website. A later update identified online reservations made from November 27, 2013, through December 24, 2014, as potentially affected.
What Park ’N Fly confirmed
In a notice filed with the California attorney general, Park ’N Fly said payment-card data processed through its e-commerce website could have been at risk. The company described the matter as a security compromise and said it had contained or addressed the issue while investigating its scope. The notice did not provide a technical description of the intrusion, identify an attacker, or establish that every potentially exposed record was taken.
The official disclosure is dated January 13, 2015. Recent breach-tracker pages can have newer crawl or update dates, but those dates do not turn this historical incident into a current breach. The state filing remains available at California’s breach-notice record.
Which reservations were in the potentially affected period?
Park ’N Fly’s later consumer update narrowed the relevant window to online reservations made between November 27, 2013, and December 24, 2014. That window concerns reservations made through the e-commerce website. It does not establish that every Park ’N Fly customer was affected or that payments made at physical parking facilities were included.
Recommended Free Tools
#1 Best Overall
The date range is reported in the company update reproduced by DataBreaches.Net. A reservation during that period indicates possible exposure, not confirmed theft or fraudulent use.
What information may have been exposed?
Park ’N Fly identified two broad categories of information as potentially at risk:
| Category | Information identified in the notice | What that means |
|---|---|---|
| Payment-card data | Card number, cardholder name, billing address, expiration date and CVV code | These elements were described as potentially at risk; the notice did not say every customer’s complete set of data was exposed. |
| Loyalty-account data | Email address, Park ’N Fly password and telephone number | The notice identified these fields as potentially exposed for loyalty customers, without confirming misuse or whether passwords were decrypted. |
The disclosure does not establish that all listed fields were taken, that every card was copied, or that possession of a CVV led to fraudulent transactions. It also does not report exposure of Social Security numbers or identity-document numbers.
How the incident came to light
Contemporaneous reporting said banks noticed a pattern of fraudulent activity on a significant number of cards that had recently been used for online reservations at Park ’N Fly locations. That account provides investigative context, not a quantified company finding or a definitive explanation of how an intruder entered the system. KrebsOnSecurity’s report also discussed a separate OneStopParking.com incident; the two companies should not be treated as one breach or as evidence of a shared attacker.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →The available public notices do not state how many customers or records were affected. The Identity Theft Resource Center’s historical listing records the number as unknown: historical breach table.
What Park ’N Fly did in response
The company’s response unfolded across the January disclosure and a February update:
Rank #3
- It engaged third-party data-forensics experts to investigate.
- It said the compromise had been contained or addressed and that website security was enhanced.
- It restored the reservations website.
- It added a PayPal-hosted payment solution as part of the later remediation.
- It established a toll-free customer call center.
- It offered 12 months of identity monitoring and identity-protection services to potentially affected customers in 2015.
- It said it was mailing notices to affected customers for whom it had current mailing addresses.
The PayPal-hosted payment change and website restoration belong to the later update, not necessarily the initial January announcement. The historical monitoring offer should not be assumed to be open for enrollment today.
What customers were told to do
Park ’N Fly’s 2015 notice advised potentially affected customers to:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →- Review payment-card and account statements for suspicious transactions.
- Contact the card issuer about the possible compromise and follow its instructions about replacement or monitoring.
- Check credit reports and remain alert for identity theft or financial fraud.
- Consider fraud alerts offered by the major credit bureaus.
- Use the company’s identity-monitoring and protection services if eligible under the 2015 offer.
The notice directed consumers to the federally authorized free-credit-report site, AnnualCreditReport.com. That address remains useful for checking reports, although any Park ’N Fly-specific monitoring benefit described in 2015 was time-limited.
Rank #4
What a former customer can still do
If you used a card during the window
Search old statements or card-account records for online Park ’N Fly reservations between November 27, 2013, and December 24, 2014. If the card account is still open, ask the issuer whether it can review historical activity or provide replacement guidance. If the account was closed, contact the former issuer if records are still available.
If you reused a Park ’N Fly password
Change that password anywhere it was reused and enable multifactor authentication where available. This is a precaution based on the disclosed possibility that Park ’N Fly loyalty passwords were at risk; it is not evidence that those passwords were actually misused.
If you are concerned about identity fraud
Review all three credit reports, consider a fraud alert or credit freeze based on your circumstances, and investigate unfamiliar accounts or inquiries promptly. The public notice does not establish exposure of Social Security numbers, so stronger identity-protection measures should be considered according to your broader risk rather than assumed necessary solely because of this incident.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
What remains unknown
- The confirmed number of affected customers or records.
- The malware, access method, attacker or exact period of unauthorized access.
- Whether particular individuals’ data was actually exfiltrated.
- Whether any specific identity theft or fraud was caused by the incident.
- Any ransom demand, regulatory penalty, lawsuit outcome or settlement.
The reservation window spans more than a year, but that does not prove continuous unauthorized access throughout the entire period. Likewise, identifying CVV as potentially at risk does not prove that every card’s CVV was copied or used.
Current status
This is a historical 2015 e-commerce payment-card incident. It should not be reported as a newly disclosed 2026 Park ’N Fly breach. Readers verifying an old reservation should focus on the specified online-reservation dates, distinguish website transactions from physical-lot payments, and treat the former 12-month monitoring offer as expired unless they have separate documentation showing otherwise.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




