HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
Francesca’s Services Corporation
bd_d5fdd211abfdc2eb · schema v1 · pii pii-v1
Full breach record for Francesca’s Services Corporation →Francesca's Services Corporation notified California regulators of a data breach involving third-party vendor Annex Cloud. Between Dec 28, 2017 and July 9, 2018, unauthorized code on the vendor's platform potentially captured customer checkout data, including names, addresses, passwords, and payment card details (including CVV). The vendor removed the code, and Francesca's removed the login feature. No specific count of affected individuals was disclosed in the filing.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_44b7acbbef0ad79eOregon State AGfiled 2018-11-19Candidate
- bd_c5a528805a38fbb5Washington State AGfiled 2018-11-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141913
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 19, 2018
- Raw hash
- 6b8696415c246c6333e299533d8fcfab7147f9e471a23bc584ffe509f07f4528
Reporting entity
- Name
- Francesca’s Services Corporationnorm: francesca s
Victim entity
- Name
- Francesca’s Services Corporationnorm: francesca s
Incident
- Discovered
- Nov 8, 2018
- Materiality determined
- Nov 15, 2018
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 11 days(11 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.