J.Crew Group, Inc.
bd_05819cd20d9fe9f2 · schema v1 · pii pii-v1
Full breach record for J.Crew Group, Inc. →J.Crew Group, Inc. notified customers of a credential-based account compromise affecting jcrew.com accounts. Stolen email/password credentials were used by an unauthorized party to log into customer accounts in or around April 2019. Accessible data included last four digits of stored credit card numbers, expiration dates, card types, billing addresses, and order/shipping information. Accounts were disabled and password resets required.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 1, 2019
Begins
Mar 2, 2020
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.