MACY'S, INC.
bd_86b831fb90eeeebf · schema v1 · pii pii-v1
Full breach record for MACY'S, INC. →5 incidents on fileMacy's disclosed a data breach involving unauthorized access to macys.com. Between October 7 and October 15, 2019, an unauthorized third party injected malicious code into the checkout and wallet pages, capturing customer PII and payment card details. Macy's engaged law enforcement and forensic investigators, removed the code, and notified affected individuals, offering 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 7, 2019
Begins
Oct 15, 2019
Discovered
Nov 14, 2019
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_62eb603410b950862019-11-14Candidate
- Washington State AGbd_e6318c97f5b749002019-11-14Verified
- California State AGbd_31b96199e68e3d552019-11-15 · +1dVerified
- Oregon State AGbd_49ff44d3a912f3e22019-11-15 · +1dVerified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- Massachusetts State AGbd_950c4ee838a9537b2019-11-15 · +1dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.