Bath & Body Works Direct, Inc.
bd_67bbd5716ecec63e · schema v1 · pii pii-v1
Full breach record for Bath & Body Works Direct, Inc. →2 incidents on fileBath & Body Works Direct, Inc. (BBW) reported a credential stuffing incident where an unauthorized party accessed online loyalty accounts between June 20 and June 25, 2021. The breach was discovered on June 23, 2021. The attacker likely used credentials stolen from another company's breach. The compromised information included names, email addresses, mailing addresses, birth day and month, phone numbers, loyalty account numbers, and linked gift card information. For customers who saved payment card details, only the last four digits were visible. In response, BBW secured the accounts, disabled passwords, and offered one year of free identity protection services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 20, 2021
Begins
Jun 23, 2021
Discovered
Aug 10, 2021
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- California State AGbd_906c68ac5dd97b3a2021-08-10Verified
- Massachusetts State AGbd_9b6c464d0a74ebd42021-08-10Verified
- Indiana State AGbd_c43c3f2459d9c74b2021-08-10Verified
- New Hampshire State AGbd_dfc77361fe0c78352021-08-13 · +3dVerified
Show 1 more filing ↓Show fewer ↑up to 221d gap
- Illinois State AGbd_586d65c613dae8212021-01-01 · +221dCandidate
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Aug 13 (NH) — a 224-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.