HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTPHILowContained
Eye Buy Direct, Inc.
bd_ab73d0fb5b5e82c7 · schema v1 · pii pii-v1
Full breach record for Eye Buy Direct, Inc. →EyeBuyDirect, Inc. notified Delaware AG of a potential cybersecurity incident involving its e-commerce platform. The company learned in June 2019 that 356 consumers reported credit card fraud linked to transactions on the EyeBuyDirect website between September 2018 and March 2019. Forensic investigators found signs of intrusion but could not confirm how, when, or if data was accessed. Potentially compromised data includes PII, prescription data, and payment card details. The incident is contained, and the company has enhanced security protections.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_f7922d53c8b8d8eaMontana State AGfiled 2019-10-14(3d gap)Candidate
- bd_7af7bf0034986af6Washington State AGfiled 2019-10-15(4d gap)Verified by operator
- bd_2dbee8db03d2d89aCalifornia State AGfiled 2019-10-18(7d gap)Verified
- bd_479cc9f8956ffdb9Oregon State AGfiled 2019-10-18(7d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2019/10/EyeBuyDirect-Exhibit-A-EBD-Notification-to-Group-1-Customers.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 11, 2019
- Raw hash
- 3dad1eb5ce4f78c6ff9f6b5e319031f92831cb9225e7b10bb933227e15792ce0
Reporting entity
- Name
- Eye Buy Direct, Inc.norm: eye buy direct
Victim entity
- Name
- Eye Buy Direct, Inc.norm: eye buy direct
Incident
- Discovered
- Jun 1, 2019
- Materiality determined
- —
- Notification sent
- Oct 1, 2019
- Affected individuals
- 356
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(132 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.