HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowActive
StockX
bd_94db413669707897 · schema v1 · pii pii-v1
Full breach record for StockX →StockX, an online marketplace, experienced a data breach where an unknown third party gained unauthorized access to customer data from its cloud environment on or around May 14, 2019. The company discovered suspicious activity on July 26, 2019, and engaged forensic experts. Affected data included names, emails, addresses, usernames, hashed passwords, and purchase history. StockX implemented security updates, password resets, and credential rotations, and notified law enforcement. The company offered 12 months of free identity theft protection to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fd5190e9e9b68673California State AGfiled 2019-08-09(1d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2019/08/StockX-Sample-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 8, 2019
- Raw hash
- 8d6bd808b178d0657425ccd4174f6ae781eda741d2f81dcac8f80acfee2564cc
Reporting entity
- Name
- StockXnorm: stockx
Victim entity
- Name
- StockXnorm: stockx
Incident
- Discovered
- Jul 26, 2019
- Materiality determined
- —
- Notification sent
- Aug 8, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified, or are notifying, appropriate regulators in the United States, the European Union, and other impacted foreign jurisdictions
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 days(13 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.