DisclosureLens
HackingRetail & ConsumerRetailSupply Chain (3P Vendor)Customer Data InvolvedFinancial accountIdentity (basic)Financial credentialsLowContained

Rhys Vineyards

bd_ab33106d9ff8398d · schema v1 · pii pii-v1

Severity

Low

Discovered

May 27, 2015

Filed

Jun 18, 2015

To disclose

22 days

Affected

Not disclosed

Confidence

65%
Full breach record for Rhys Vineyards2 incidents on file

Rhys Vineyards notified customers of a security incident involving its third-party ecommerce provider, Missing Link Networks, Inc. Unauthorized access to credit/debit card data, names, passwords, and dates of birth may have occurred between April 1 and April 30, 2015. Rhys was notified by Missing Link on May 27, 2015. The breach has been contained. Customers were advised to update passwords and monitor accounts.

Incident timeline

undetected · 56 days
discovery → filing · 22 days

Apr 1, 2015

Begins

May 27, 2015

Discovered

Jun 18, 2015

Filed

vs. sector median

4 wks faster

Part of Missing Link Network supply-chain incident (2015) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.