Best Buy Co., Inc.
bd_abf1ad4c92fe5228 · schema v1 · pii pii-v1
Full breach record for Best Buy Co., Inc. →5 incidents on fileBest Buy Co., Inc. notified customers that a third-party vendor, [24]7.ai, suffered a cyber intrusion in which malicious code was inserted into its customer service chat software between September 26 and October 12, 2017. The code enabled unauthorized access to payment card information (name, address, card number, expiration date, security code) of BestBuy.com customers. Best Buy publicly disclosed on April 5, 2018 and sent consumer notifications April 12, 2018. Identity Guard credit monitoring offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 26, 2017
Begins
Apr 13, 2018
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Washington State AGbd_3d9c5856ad205a4c2018-04-13Verified by operator
- Massachusetts State AGbd_8fa5e4e8d23657b22018-04-13Verified
- New Hampshire State AGbd_aed67aaeddf0751b2018-04-13Verified
- Montana State AGbd_935b6af16c9aadf62018-04-12 · +1dCandidate
Show 1 more filing ↓Show fewer ↑up to 12d gap
- Oregon State AGbd_3127e7742cdefbe02018-04-25 · +12dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Apr 12 (MT), last Apr 25 (OR) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.