HackingStolen CredentialsCustomer Data InvolvedCREDENTIALSIDENTITY_BASICLowContained
Toys "R" US-Delaware, Inc.
bd_4f7612e412730521 · schema v1 · pii pii-v1
Full breach record for Toys "R" US-Delaware, Inc. →Toys 'R' Us-Delaware, Inc. reported unauthorized access to a small percentage of Rewards 'R' Us accounts between January 28 and January 30, 2015. The company suspects the activity was due to credential stuffing using login names and passwords stolen from breaches at other companies. Affected data included account passwords and profile information. The company forced a hard password reset for affected accounts.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-48551
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2015
- Raw hash
- 9849097e1ce0a86191a526c957f17723d9c3f61784e1e9695697939b19c1d818
Reporting entity
- Name
- Toys "R" US-Delaware, Inc.norm: toys r us delaware
Victim entity
- Name
- Toys "R" US-Delaware, Inc.norm: toys r us delaware
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Feb 1, 2015
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.