HackingVulnerability ExploitCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
CALERES, INC.
bd_d948faec8324961d · schema v1 · pii pii-v1
Full breach record for CALERES, INC. →Caleres, Inc. disclosed that an unauthorized party gained access to certain websites between July 7 and July 18, 2023. The incident may have involved payment card information, including name, address, zip code, payment card number, expiration date, and CVV. Caleres engaged a cybersecurity firm and enhanced security protocols.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_16a515f94765b134Vermont State AGfiled 2023-09-01Verified
- bd_813eae7615bf4ad1Maine State AGfiled 2023-09-01Candidate
- bd_ea19496ed9ae012eMontana State AGfiled 2023-09-01Verified
- bd_fe33e88e2bce7f2dNew Hampshire State AGfiled 2023-09-01Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572780
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2023
- Raw hash
- 3fd17d7d2b128c6a479692076407f10d8c2247e3cd30850bdefb7e48231447f3
Reporting entity
- Name
- CALERES, INC.norm: caleres
Victim entity
- Name
- CALERES, INC.norm: caleres
Incident
- Discovered
- Jul 18, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.