HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Toys "R" US-Delaware, Inc.
bd_5eb3a091db9f2144 · schema v1 · pii pii-v1
Full breach record for Toys "R" US-Delaware, Inc. →Toys "R" Us-Delaware, Inc. reported unauthorized access to Rewards"R"Us loyalty program accounts between November 11, 2016, and January 17, 2017. The incident involved the use of stolen credentials from other breaches to fraudulently redeem reward coupons and gift cards. Affected data included names, email addresses, mailing addresses, phone numbers, and potentially children's names and birth dates. No credit card or SSN data was stored. The company reset passwords and reinstated points/gift cards.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66154
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 2, 2017
- Raw hash
- 8eb35864da6070060e427201895289383d2881cdc919ed4acd4f900c0d331069
Reporting entity
- Name
- Toys "R" US-Delaware, Inc.norm: toys r us delaware
Victim entity
- Name
- Toys "R" US-Delaware, Inc.norm: toys r us delaware
Incident
- Discovered
- Jan 17, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.