HackingRetail & ConsumerRetailSkimmerCapture App DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPIIPCILowContained
STEIN MART, INC.
bd_8a74ba926b9e0e7f · schema v1 · pii pii-v1
Full breach record for STEIN MART, INC. →Stein Mart, Inc. notified customers of a web skimmer incident involving their third-party vendor Annex Cloud. Unauthorized code was added to Annex Cloud's login integration on steinmart.com and could have captured checkout information including name, address, email, payment card number, expiration date, and CVV during multiple periods between December 28, 2017 and July 9, 2018.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7be7408ca1651613Montana State AGfiled 2018-11-13Candidate
- bd_dcd4b744c7396396Washington State AGfiled 2018-11-13Verified by operator
- bd_f55c7eaa8530a3afOregon State AGfiled 2018-11-13Verified by operator
- bd_f29c876cc79bf670California State AGfiled 2018-11-27(14d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141776
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2018
- Raw hash
- 5d980584047ef86f147a2368d004913aeb0fa8c156694cdbf1a8d11d5a8dfb25
Reporting entity
- Name
- STEIN MART, INC.norm: stein mart
Victim entity
- Name
- STEIN MART, INC.norm: stein mart
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPIIPCI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1056 Input CaptureT1074 Data Staged
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney General
- Third party
- via Annex Cloud
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.