HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Lulu's Fashion Lounge
bd_64630f2a60519789 · schema v1 · pii pii-v1
Full breach record for Lulu's Fashion Lounge →Lulu's Fashion Lounge, Inc. notified the NH Attorney General of a data security incident affecting 46 NH residents. Unauthorized access to the payment card processing system occurred between August 11-16, 2016. Compromised data included names, billing addresses, and payment card details (number, security code, expiration). Notifications were mailed on September 16, 2016.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3021ba4889609053California State AGfiled 2016-09-16Verified
- bd_ab508a8df133c2aeMontana State AGfiled 2016-09-16Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lulus-fashion-20160916.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 16, 2016
- Raw hash
- f363ccda976003a9567b6a6fa0fef86bd8a6c9854aab64db2159243622f63315
Reporting entity
- Name
- ID Expertsnorm: id experts
Victim entity
- Name
- Lulu's Fashion Loungenorm: lulu s fashion lounge
Incident
- Discovered
- Aug 23, 2016
- Materiality determined
- —
- Notification sent
- Sep 16, 2016
- Affected individuals
- 46
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.