DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsCustomer Data InvolvedPIIIdentity (basic)Financial accountCredentialsLowContained

My Favorite Things

bd_aac23ed690a997f8 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Dec 7, 2017

To disclose

Affected

10state residents only

Confidence

66%

My Favorite Things (MFT) notified customers that their electronic order and payment system was compromised between June 22, 2017, and August 15, 2017. The breach likely involved compromised vendor credentials, exposing names, billing/shipping addresses, credit card info, and contact details. MFT engaged forensic investigators, removed malware, reset credentials, and offered one year of credit monitoring.

Incident timeline

Jun 22, 2017

Begins

Dec 7, 2017

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed10 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.