HackingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
CALERES, INC.
bd_16a515f94765b134 · schema v1 · pii pii-v1
Full breach record for CALERES, INC. →Caleres, Inc. disclosed a security incident affecting its websites (including Famous Footwear, Sam Edelman, and Allen Edmonds) between July 7 and July 18, 2023. Unauthorized parties gained access to payment card data, including names, addresses, card numbers, expiration dates, and CVVs. Caleres engaged a cybersecurity firm, enhanced security protocols, and established a call center. No specific affected individual count was provided in the notice.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_813eae7615bf4ad1Maine State AGfiled 2023-09-01Candidate
- bd_d948faec8324961dCalifornia State AGfiled 2023-09-01Verified
- bd_ea19496ed9ae012eMontana State AGfiled 2023-09-01Verified
- bd_fe33e88e2bce7f2dNew Hampshire State AGfiled 2023-09-01Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-01-caleres-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2023
- Raw hash
- 6d6a63df3686c8abee43c644d05150cddde3134b9d6a5bde5932aeb5fe7ca805
Reporting entity
- Name
- CALERES, INC.norm: caleres
Victim entity
- Name
- CALERES, INC.norm: caleres
Incident
- Discovered
- Jul 18, 2023
- Materiality determined
- —
- Notification sent
- Sep 1, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.