DisclosureLens
MisuseRetail & ConsumerRetailPrivilege AbuseEmployee Data InvolvedFinancial accountPIILowContained

BED BATH & BEYOND, INC.

bd_482b888d43d91669 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

May 5, 2019

To disclose

Affected · nationwide

3462 in this filing

Linked

2 filings

Confidence

66%
Full breach record for BED BATH & BEYOND, INC.12 incidents on file

Bed Bath & Beyond notified the NH AG of a potential insider threat involving one call center employee who may have attempted to illegally compromise customer credit card information. The incident occurred between June 19, 2018, and March 26, 2019. The employee was terminated and legal action is being taken. Notifications were sent to 346 individuals, including 2 NH residents, offering one year of credit monitoring.

Incident timeline

Jun 19, 2018

Begins

May 5, 2019

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AG+2d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.