MACY'S, INC.
bd_1b586ea053ae9b1e · schema v1 · pii pii-v1
Full breach record for MACY'S, INC. →5 incidents on fileMacy's, Inc. reported a cyberattack where an unauthorized third party used stolen valid credentials to access customer profiles on macys.com and bloomingdales.com. The incident occurred from April 26 to June 12, 2018, and was detected on June 11, 2018. The attacker accessed names, addresses, emails, phone numbers, and attempted to access payment card data. 3,564 Washington residents were notified.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 26, 2018
Begins
Jun 11, 2018
Discovered
Jul 1, 2018
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_394c9bfca4d45f0d2018-07-02 · +1dVerified
- New Hampshire State AGbd_5df1dd8fcc86bf932018-07-02 · +1dVerified
- Massachusetts State AGbd_aafec7407e6af25a2018-07-02 · +1dVerified
- California State AGbd_df0d139238bc78a52018-07-02 · +1dVerified
Show 1 more filing ↓Show fewer ↑up to 2d gap
- Oregon State AGbd_d0d676c1d1a62f7f2018-07-03 · +2dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.