DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Financial accountFinancial credentialsCredentialsLowContained

Francesca’s Services Corporation

bd_d5fdd211abfdc2eb · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Nov 19, 2018

To disclose

Affected

Not disclosed

Confidence

65%
Full breach record for Francesca’s Services Corporation2 incidents on file

Francesca’s Services Corporation notified customers of a data breach involving its third-party vendor, Annex Cloud. Unauthorized code detected on Annex Cloud’s login service between December 28, 2017, and July 9, 2018, may have captured checkout information including names, addresses, emails, passwords, and payment card details (number, expiration, CVV). Francesca’s removed the Annex Cloud login feature and advised customers to reset passwords and monitor statements.

Incident timeline

Dec 28, 2017

Begins

Nov 19, 2018

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.