HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Coyuchi
bd_ac2a7e9bf5c00edb · schema v1 · pii pii-v1
Full breach record for Coyuchi →Coyuchi, a retail company, disclosed a data breach occurring from June 20, 2019, to July 18, 2019. Malicious code was placed on their website to collect customer checkout data, including names, addresses, emails, and payment card details. The breach was discovered via an anti-virus alert and the code was removed. Coyuchi engaged Kroll to provide one year of complimentary identity monitoring services to affected customers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-150477
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2019
- Raw hash
- 882f94c929fe30bcf3a71416d89181a411d930eb560fd15156c0e1071932e83f
Reporting entity
- Name
- Coyuchinorm: coyuchi
- Domain
- coyuchi.com
Victim entity
- Name
- Coyuchinorm: coyuchi
- Domain
- coyuchi.com
Incident
- Discovered
- Jul 18, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.