HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Eddie Bauer
bd_0f9818a67b1c51e4 · schema v1 · pii pii-v1
Full breach record for Eddie Bauer →Eddie Bauer, LLC reported a data security incident involving unauthorized access to point-of-sale systems at retail stores between January 2, 2016, and July 17, 2016. The breach potentially exposed payment card numbers, security codes, expiration dates, and customer names. Eddie Bauer engaged forensic experts, notified the FBI and payment card networks, and provided 12 months of complimentary credit monitoring and identity restoration services through Kroll to affected individuals.
California clockDiscovered Aug 11, 2016 → Notified Aug 18, 20167d ✓ CA 60-day OK7 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0beaa4320009e304Oregon State AGfiled 2016-08-18Candidate
- bd_380bb2dab0ef39caNew Hampshire State AGfiled 2016-08-18Verified
- bd_da7886c5b1e299c8Washington State AGfiled 2016-08-18Verified
- bd_e71f9c9561385067Montana State AGfiled 2016-08-19(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63417
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 18, 2016
- Raw hash
- 39fb0034fb813b4fb0bb7a06ca72434a35e7830ab1b45363052595422ea66445
Reporting entity
- Name
- Eddie Bauernorm: eddie bauer
- Domain
- eddiebauer.com
Victim entity
- Name
- Eddie Bauernorm: eddie bauer
- Domain
- eddiebauer.com
Incident
- Discovered
- Aug 11, 2016
- Materiality determined
- —
- Notification sent
- Aug 18, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- working closely with the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 7d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 11, 2016→ Notified: Aug 18, 20167d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.