Bath & Body Works Direct, Inc.
bd_906c68ac5dd97b3a · schema v1 · pii pii-v1
Full breach record for Bath & Body Works Direct, Inc. →2 incidents on fileBath & Body Works Direct, Inc. reported that an unauthorized party accessed personal information in online loyalty accounts between June 20 and June 25, 2021. The breach resulted from credential reuse from a third-party system breach. Affected data included names, email addresses, mailing addresses, birth day/month, telephone numbers, loyalty account numbers, and gift card PINs. Only the last four digits of saved payment cards were visible. The company reset passwords, coordinated with law enforcement, and offered one year of identity protection.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 20, 2021
Begins
Aug 10, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_67bbd5716ecec63e2021-08-10Verified
- Massachusetts State AGbd_9b6c464d0a74ebd42021-08-10Verified
- Indiana State AGbd_c43c3f2459d9c74b2021-08-10Verified
- New Hampshire State AGbd_dfc77361fe0c78352021-08-13 · +3dVerified
Show 1 more filing ↓Show fewer ↑up to 221d gap
- Illinois State AGbd_586d65c613dae8212021-01-01 · +221dCandidate
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Aug 13 (NH) — a 224-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.