DisclosureLens
MalwareRetail & ConsumerRetailStolen CredentialsInfostealerData ExfiltratedCustomer Data InvolvedDelayed DiscoveryFinancial accountFinancial credentialsIdentity (basic)CredentialsMediumContained

Jewelry.com, a division of Richline Group, Inc.

bd_cb446a131e6c5dea · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 16, 2017

Filed

Jun 17, 2017

To disclose

5 weeks

Affected · nationwide

7,000619 in this filing

Confidence

66%
Full breach record for Jewelry.com, a division of Richline Group, Inc.2 incidents on file

Jewelry.com discovered on May 16, 2017, that unknown individuals gained unauthorized access to its online boutique starting November 16, 2016, via an employee account. Malicious software was installed to capture credit card payment information (card numbers, names, billing addresses, passwords, security codes, expiration dates) from the shopping cart page. The breach affected approximately 7,000 individuals nationwide, including 619 California residents. The company removed the malware, terminated the compromised account, and reported the incident to law enforcement.

Incident timeline

undetected · 181 days
discovery → filing · 5 weeks / 32 days

Nov 16, 2016

Begins

May 16, 2017

Discovered

Jun 17, 2017

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,000 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.