HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
macys.com
bd_86b831fb90eeeebf · schema v1 · pii pii-v1
Full breach record for macys.com →Macy's disclosed a data breach involving unauthorized access to macys.com. Between October 7 and October 15, 2019, an unauthorized third party injected malicious code into the checkout and wallet pages, capturing customer PII and payment card details. Macy's engaged law enforcement and forensic investigators, removed the code, and notified affected individuals, offering 12 months of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_31b96199e68e3d55California State AGfiled 2019-11-15(1d gap)Verified
- bd_49ff44d3a912f3e2Oregon State AGfiled 2019-11-15(1d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/06/Macys.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 14, 2019
- Raw hash
- e806f75cd7c6511d67d5146c3c31b5a7533accb35c2d033bef3dd6ce6db47239
Reporting entity
- Name
- macys.comnorm: macyscom
- Domain
- macys.com
Victim entity
- Name
- macys.comnorm: macyscom
- Domain
- macys.com
Incident
- Discovered
- Oct 15, 2019
- Materiality determined
- —
- Notification sent
- Nov 14, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.