HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Bath & Body Works Direct, Inc.
bd_906c68ac5dd97b3a · schema v1 · pii pii-v1
Full breach record for Bath & Body Works Direct, Inc. →Bath & Body Works Direct, Inc. disclosed a cybersecurity incident affecting online loyalty accounts between June 20 and June 25, 2021. An unauthorized party accessed data by exploiting credentials stolen from a third-party breach. Affected data included names, emails, addresses, phone numbers, loyalty numbers, and partial payment card digits. The company disabled passwords, coordinated with law enforcement, and offered one year of free identity protection services.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_67bbd5716ecec63eMaine State AGfiled 2021-08-10Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-543767
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 10, 2021
- Raw hash
- d81c22b93bf7831f65f888586e52acadebccd85d9a7e3cbb684ea78814b0403d
Reporting entity
- Name
- Bath & Body Works Direct, Inc.norm: bath body works direct
Victim entity
- Name
- Bath & Body Works Direct, Inc.norm: bath body works direct
Incident
- Discovered
- Jun 25, 2021
- Materiality determined
- Aug 10, 2021
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.