HackingRetail & ConsumerRetailBackdoor / C2Capture App DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Best Buy Co., Inc.
bd_abf1ad4c92fe5228 · schema v1 · pii pii-v1
Full breach record for Best Buy Co., Inc. →Best Buy Co., Inc. notified customers that a third-party vendor, [24]7.ai, suffered a cyber intrusion in which malicious code was inserted into its customer service chat software between September 26 and October 12, 2017. The code enabled unauthorized access to payment card information (name, address, card number, expiration date, security code) of BestBuy.com customers. Best Buy publicly disclosed on April 5, 2018 and sent consumer notifications April 12, 2018. Identity Guard credit monitoring offered to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3d9c5856ad205a4cWashington State AGfiled 2018-04-13Verified by operator
- bd_935b6af16c9aadf6Montana State AGfiled 2018-04-12(1d gap)Candidate
- bd_3127e7742cdefbe0Oregon State AGfiled 2018-04-25(12d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-135278
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 13, 2018
- Raw hash
- 57102a16d773e340ef823c7833f2d390d8417af602e4882fbe388b4fe7a23c62
Reporting entity
- Name
- Best Buy Co., Inc.norm: best buy
Victim entity
- Name
- Best Buy Co., Inc.norm: best buy
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Apr 12, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Third party
- via [24]7.ai
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.