Gloria Jean's Coffees
bd_bf1f619e331d2202 · schema v1 · pii pii-v1
Full breach record for Gloria Jean's Coffees →Gloria Jean's Coffee experienced a data breach affecting its e-commerce site hosted by Smith Micro, Inc. Between September 4 and September 10, 2008, an unauthorized individual modified checkout web pages to capture and exfiltrate customer transaction information, including names, addresses, and credit card numbers. The intrusion was identified on September 10, 2008. A total of 511 customers were affected nationwide, including 19 residents of New Hampshire. The company took the website offline, removed malicious code, disabled the attacker's IP, and reported the incident to the US Secret Service. No fraudulent transactions were confirmed at the time of notification.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 4, 2008
Begins
Sep 10, 2008
Discovered
Sep 17, 2008
Filed
vs. sector median
7 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.