DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsCapture Stored DataAspxspyData ExfiltratedCustomer Data InvolvedDelayed DiscoveryMulti-Stage ChainAuthenticationCredentialsFinancial accountIdentity (basic)PIIMediumContained

Bailey's I, LLC

bd_9f3d217e0842e583 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 1, 2015

Filed

Mar 14, 2016

To disclose

15 weeks

Affected · nationwide

15,0008,844 in this filing

Linked

2 filings

Confidence

68%
Full breach record for Bailey's I, LLC3 incidents on file

Bailey's, Inc. disclosed a cyberattack on BaileysOnline.com where attackers exploited a Windows 2008 defect to install ASPXSPY malware and capture keystrokes. The incident occurred between Dec 2011 and Jan 2016, with discovery in Dec 2015. Approximately 15,000 credit cards were compromised, including 8,844 in Washington. Data included card numbers, names, passwords, and addresses. No SSNs or bank accounts were taken. The company engaged forensic consultants and law enforcement.

Incident timeline

undetected · 1461 days
discovery → filing · 15 weeks / 104 days

Dec 1, 2011

Begins

Dec 1, 2015

Discovered

Mar 14, 2016

Filed

vs. sector median

+7 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
California State AGMar 14 · first
Washington State AGMar 14 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.