HackingStolen CredentialsTargetedCustomer Data InvolvedIDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNTLowContained
Dollar Shave Club, Inc.
bd_ebdfc1c9e7488eb5 · schema v1 · pii pii-v1
Full breach record for Dollar Shave Club, Inc. →Dollar Shave Club, Inc. notified California residents that on March 21, 2018, attackers used email and password combinations obtained from other sources to attempt unauthorized access to customer accounts. The company blocked the attacks, reset passwords for impacted accounts, and limited login attempts. Affected data included names, addresses, last four digits of payment cards, and credentials. No full payment card numbers or unauthorized purchases were observed.
California clockDiscovered Mar 21, 2018 → Notified Mar 22, 20180d ✓ CA 60-day OK13 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-135044
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 4, 2018
- Raw hash
- ced35222565d19413bd7c5fede2769f4e80c879565947cbe9c008ad36122e27d
Reporting entity
- Name
- Dollar Shave Club, Inc.norm: dollar shave club
- Domain
- dollarshaveclub.com
Victim entity
- Name
- Dollar Shave Club, Inc.norm: dollar shave club
- Domain
- dollarshaveclub.com
Incident
- Discovered
- Mar 21, 2018
- Materiality determined
- Mar 22, 2018
- Notification sent
- Mar 22, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed Data Security Breach Notification with California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 days(13 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 21, 2018→ Notified: Mar 22, 20180d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.