HackingIDENTITY_BASICLowContained
Rent the Runway, Inc.
bd_4f54daed2d2b921f · schema v1 · pii pii-v1
Full breach record for Rent the Runway, Inc. →Rent the Runway disclosed a cybersecurity incident where an unknown party accessed customer accounts between December 25, 2016, and February 23, 2017. The breach exposed email addresses, names, birthdays, and mailing addresses. No credit card information was stored or exposed. The company locked and reset affected passwords, implemented new security measures, and notified customers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-67055
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2017
- Raw hash
- 052eadd2ec248eb131e120f0421ad704bac3a1e5032d33da41363df6953764d2
Reporting entity
- Name
- Rent the Runway, Inc.norm: rent the runway
Victim entity
- Name
- Rent the Runway, Inc.norm: rent the runway
Incident
- Discovered
- Feb 23, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.