Best Buy Co., Inc.
bd_c151e1ec0393f78d · schema v1 · pii pii-v1
Full breach record for Best Buy Co., Inc. →5 incidents on fileBest Buy notified customers of a data breach involving third-party vendor [24]7.ai. Malicious code inserted in vendor software between Sept 26 and Oct 12, 2017, allowed unauthorized access to payment card data (names, addresses, card numbers, CVV) for customers shopping on BestBuy.com during that period. Best Buy engaged forensic experts, removed the code, and offered 1 year of credit monitoring via Identity Guard.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 26, 2017
Begins
Oct 12, 2017
Discovered
Apr 17, 2018
Filed
vs. sector median
+19 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.