HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Eileen Fisher, Inc.
bd_07551083dc03afc2 · schema v1 · pii pii-v1
Full breach record for Eileen Fisher, Inc. →Eileen Fisher reported a data breach affecting customers who made purchases on eileenfisher.com between September 7 and October 24, 2016. Malicious code was added to the website, allowing unauthorized capture of names, shipping/billing addresses, and credit card numbers. The company engaged a forensics firm, removed the code, and provided 12 months of free identity monitoring via AllClear ID.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_14199a240fd64480Oregon State AGfiled 2016-11-09Candidate
- bd_669ebe1f9a968f36Montana State AGfiled 2016-11-09Verified
- bd_7ce569c59d55c2e5Washington State AGfiled 2016-11-09Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64832
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 9, 2016
- Raw hash
- 5790180e9554cf01e377ee6471b771e7be8c536497bf8eb7e474733d477957f1
Reporting entity
- Name
- Eileen Fisher, Inc.norm: eileen fisher
- Domain
- eileenfisher.com
Victim entity
- Name
- Eileen Fisher, Inc.norm: eileen fisher
- Domain
- eileenfisher.com
Incident
- Discovered
- Oct 24, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.