HackingRetail & ConsumerRetailStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryCREDENTIALSFINANCIAL_ACCOUNTPIIIDENTITY_BASICLowContained
J.Crew Group, Inc.
bd_05819cd20d9fe9f2 · schema v1 · pii pii-v1
Full breach record for J.Crew Group, Inc. →J.Crew Group, Inc. notified customers of a credential-based account compromise affecting jcrew.com accounts. Stolen email/password credentials were used by an unauthorized party to log into customer accounts in or around April 2019. Accessible data included last four digits of stored credit card numbers, expiration dates, card types, billing addresses, and order/shipping information. Accounts were disabled and password resets required.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-187838
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2020
- Raw hash
- b07eac948feff62642dfe2463b75e97d01ba9575fb5b66e95a3b34df965772bd
Reporting entity
- Name
- J.Crew Group, Inc.norm: jcrew group
- Domain
- jcrew.com
Victim entity
- Name
- J.Crew Group, Inc.norm: jcrew group
- Domain
- jcrew.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSFINANCIAL_ACCOUNTPIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.