HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTCREDENTIALSIDENTITY_BASICMediumContained
Jewelry.com, a division of Richline Group, Inc.
bd_cb446a131e6c5dea · schema v1 · pii pii-v1
Full breach record for Jewelry.com, a division of Richline Group, Inc. →Jewelry.com, a division of Richline Group, Inc., disclosed a data breach affecting approximately 7,000 individuals (619 in California). Between November 16, 2016, and May 1, 2017, unauthorized individuals used a compromised employee account to install malicious software on the Jewelry.com website, capturing credit card numbers, security codes, expiration dates, names, and billing addresses. The company removed the malware, terminated the account, disabled the affected computer, retained legal counsel, and notified law enforcement.
California clockDiscovered May 16, 2017 → Notified May 16, 20170d ✓ CA 60-day OK5 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,000 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-97480
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 17, 2017
- Raw hash
- c9fe4a9bb6cede77ae02f44af4be62b96375bfefebbe369aa8489e3d6f982154
Reporting entity
- Name
- Jewelry.com, a division of Richline Group, Inc.norm: jewelrycom a division of richline
- Industry
- retail_consumer
Victim entity
- Name
- Jewelry.com, a division of Richline Group, Inc.norm: jewelrycom a division of richline
- Industry
- retail_consumer
Incident
- Discovered
- May 16, 2017
- Materiality determined
- —
- Notification sent
- May 16, 2017
- Affected individuals
- 7,000
- Data types
- FINANCIAL_ACCOUNTCREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to the appropriate federal and state law enforcement authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 16, 2017→ Notified: May 16, 20170d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.