Best Buy Co., Inc.
bd_aed67aaeddf0751b · schema v1 · pii pii-v1
Full breach record for Best Buy Co., Inc. →5 incidents on fileBest Buy Co., Inc. notified the NH AG of a data breach involving third-party vendor [24]7.ai. Malicious code inserted between Sept 26 and Oct 12, 2017, allowed unauthorized access to customer payment card info (names, addresses, card numbers, CVV) for shoppers on BestBuy.com during that window. Best Buy engaged forensic experts, removed the code, and changed software operations. No count of affected individuals was provided.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 26, 2017
Begins
Mar 1, 2018
Discovered
Apr 13, 2018
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Washington State AGbd_3d9c5856ad205a4c2018-04-13Verified by operator
- Massachusetts State AGbd_8fa5e4e8d23657b22018-04-13Verified
- California State AGbd_abf1ad4c92fe52282018-04-13Verified
- Montana State AGbd_935b6af16c9aadf62018-04-12 · +1dCandidate
Show 1 more filing ↓Show fewer ↑up to 12d gap
- Oregon State AGbd_3127e7742cdefbe02018-04-25 · +12dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Apr 12 (MT), last Apr 25 (OR) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.