HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
macys.com
bd_31b96199e68e3d55 · schema v1 · pii pii-v1
Full breach record for macys.com →macys.com experienced a data breach between October 7 and October 15, 2019, where an unauthorized third party injected malicious code into checkout and wallet pages to capture customer PII and payment card data. The incident was contained on October 15, 2019. Affected data included names, addresses, phone numbers, email addresses, payment card numbers, and security codes. Macy's engaged forensic investigators, notified law enforcement, reported card numbers to card brands, and provided 12 months of free identity protection services via Experian IdentityWorks.
California clockDiscovered Oct 15, 2019 → Notified Nov 14, 201930d ✓ CA 60-day OK4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_49ff44d3a912f3e2Oregon State AGfiled 2019-11-15Candidate
- bd_86b831fb90eeeebfDelaware State AGfiled 2019-11-14(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-184363
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 15, 2019
- Raw hash
- 2f0d30cfb962948cbcf0e067ba9b1341bd6bbfd21200f952b702c3a7558d828c
Reporting entity
- Name
- macys.comnorm: macyscom
- Domain
- macys.com
Victim entity
- Name
- macys.comnorm: macyscom
- Domain
- macys.com
Incident
- Discovered
- Oct 15, 2019
- Materiality determined
- —
- Notification sent
- Nov 14, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 15, 2019→ Notified: Nov 14, 201930d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.