DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountMediumContained

Best Buy Co., Inc.

bd_c151e1ec0393f78d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 12, 2017

Filed

Apr 17, 2018

To disclose

27 weeks

Affected

4,716state residents only

Confidence

64%
Full breach record for Best Buy Co., Inc.5 incidents on file

Best Buy notified customers of a data breach involving third-party vendor [24]7.ai. Malicious code inserted in vendor software between Sept 26 and Oct 12, 2017, allowed unauthorized access to payment card data (names, addresses, card numbers, CVV) for customers shopping on BestBuy.com during that period. Best Buy engaged forensic experts, removed the code, and offered 1 year of credit monitoring via Identity Guard.

South Carolina clock SC CRA notice due27 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 16 days
discovery → filing · 27 weeks / 187 days

Sep 26, 2017

Begins

Oct 12, 2017

Discovered

Apr 17, 2018

Filed

vs. sector median

+19 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,716 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.