Francesca’s Services Corporation
bd_d5fdd211abfdc2eb · schema v1 · pii pii-v1
Full breach record for Francesca’s Services Corporation →2 incidents on fileFrancesca’s Services Corporation notified customers of a data breach involving its third-party vendor, Annex Cloud. Unauthorized code detected on Annex Cloud’s login service between December 28, 2017, and July 9, 2018, may have captured checkout information including names, addresses, emails, passwords, and payment card details (number, expiration, CVV). Francesca’s removed the Annex Cloud login feature and advised customers to reset passwords and monitor statements.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 28, 2017
Begins
Nov 19, 2018
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.