HackingVulnerability ExploitStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedCREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Tween Brands, Inc.
bd_0c7c4e17c082f7c7 · schema v1 · pii pii-v1
Full breach record for Tween Brands, Inc. →Tween Brands, Inc. discovered unauthorized access to a web server on September 7, 2017. An attacker may have accessed a database containing vendor portal credentials (usernames/passwords) and associate data (names, dates of birth, SSNs). The company removed the server, engaged forensics, and offered 12 months of identity protection to affected associates.
California clockDiscovered Sep 7, 2017 → Notified Nov 3, 201757d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5590b1b5d1a2d26aOregon State AGfiled 2017-11-03Candidate
- bd_634cff86f41633eaWashington State AGfiled 2017-11-03Verified
- bd_b8ebda01353bd6dcMontana State AGfiled 2017-11-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-103242
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2017
- Raw hash
- aa9116514cfb86e9145fcdebcb3068561e2a8a3e2320ebf860927bfcdfae8dba
Reporting entity
- Name
- Tween Brands, Inc.norm: tween brands
Victim entity
- Name
- Tween Brands, Inc.norm: tween brands
Incident
- Discovered
- Sep 7, 2017
- Materiality determined
- —
- Notification sent
- Nov 3, 2017
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 57d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 7, 2017→ Notified: Nov 3, 201757d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.