HackingStolen CredentialsCustomer Data InvolvedCREDENTIALSAUTHENTICATIONLowContained
BED BATH & BEYOND, INC.
bd_e60050beb1dab39b · schema v1 · pii pii-v1
Full breach record for BED BATH & BEYOND, INC. →Bed Bath & Beyond Inc. disclosed that a third party used email and password information acquired outside the company to access a limited number of online accounts between September 4 and September 27, 2019. Security Challenge Questions and Answers may have been visible. Payment cards were not compromised. The company conducted an internal investigation, retained a forensics firm, and implemented enhanced security measures. Affected customers were advised to reset passwords and change security questions.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-183914
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 29, 2019
- Raw hash
- 1f4c0b649d43fd125942a5b1b89e839d80f63c4cf79637a9fb168144999d8115
Reporting entity
- Name
- BED BATH & BEYOND, INC.norm: bed bath beyond
- Domain
- bedbathandbeyond.com
Victim entity
- Name
- BED BATH & BEYOND, INC.norm: bed bath beyond
- Domain
- bedbathandbeyond.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Oct 29, 2019
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.