HackingRetail & ConsumerRetailCapture Stored DataData ExfiltratedEmployee Data InvolvedPIIIDENTITY_BASICEMPLOYMENTLowContained
Citi Trends, Inc.
bd_227f63a14d300e6a · schema v1 · pii pii-v1
Full breach record for Citi Trends, Inc. →On or about January 14, 2023, an unauthorized third party entered and disrupted Citi Trends, Inc.'s IT network, gaining the ability to extract data including files containing employee and prospective employee information (names and other employment-related details). The company responded by changing passwords, blocking access, and engaging outside technical experts. Affected individuals were offered Experian credit monitoring and identity theft insurance.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_2112802b15c24077Leak Sitehunters_internationalfiled 2024-04-03(287d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-568353
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 22, 2023
- Raw hash
- 3afc3df309df6d176310330c10a895932d8a770c4c3eaca0ae651f2198368d30
Reporting entity
- Name
- Citi Trends, Inc.norm: citi trends
- Domain
- cititrends.com
Victim entity
- Name
- Citi Trends, Inc.norm: citi trends
- Domain
- cititrends.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.