Newegg
bd_ca430b5da11acb10 · schema v1 · pii pii-v1
Full breach record for Newegg →Newegg, Inc. notified customers of unauthorized access to its website servers between August 13 and September 19, 2018. Attackers modified the checkout page to capture order information, including names, addresses, and full payment card details (number, expiration, CVV2). Newegg engaged a security firm, removed malicious code, and notified law enforcement and card networks. Investigation confirmed on October 15, 2018.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 13, 2018
Begins
Sep 18, 2018
Discovered
Nov 19, 2018
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_8cf4690e2bfa0d582018-11-16 · +3dVerified
- Washington State AGbd_29aeda114baf466a2018-11-15 · +4dCandidate
- Massachusetts State AGbd_5fcd1beca9affe212018-11-15 · +4dVerified
- Montana State AGbd_95f9e8a39b66d2b32018-11-15 · +4dVerified
Show 2 more filings ↓Show fewer ↑up to 4d gap
- California State AGbd_a5549910906d4da92018-11-15 · +4dVerified
- Oregon State AGbd_b76f58fed4feb2d02018-11-15 · +4dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.