AccidentalProgramming ErrorCustomer Data InvolvedCREDENTIALSLowResolved
W.W. GRAINGER, INC.
bd_3e1741dd5ceca12e · schema v1 · pii pii-v1
Full breach record for W.W. GRAINGER, INC. →W.W. Grainger, Inc. identified a coding error in its mobile apps that resulted in the unsecured storage of usernames and passwords. The issue was discovered on October 27, 2015, and immediately fixed. No payment card or other personal information was affected. Passwords were reset as a precaution.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-58923
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2015
- Raw hash
- 3d3fcebb2fa3aa617d84bad586ccfffbc8872a0ece14ca6397c58429713238f7
Reporting entity
- Name
- W.W. GRAINGER, INC.norm: ww grainger
- Domain
- grainger.com
Victim entity
- Name
- W.W. GRAINGER, INC.norm: ww grainger
- Domain
- grainger.com
Incident
- Discovered
- Oct 27, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALS
- Attack vector
- Unknown
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.