HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATIONLowContained
STEIN MART, INC.
bd_f29c876cc79bf670 · schema v1 · pii pii-v1
Full breach record for STEIN MART, INC. →Synchrony Bank reported a breach affecting Stein Mart, Inc. customers. Unauthorized code injected by a third-party vendor into Stein Mart's website between Dec 2017 and Jul 2018 targeted credit card data. Affected data included names, addresses, emails, credit card numbers, security codes, and expiration dates. Synchrony Bank issued new cards and offered credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7be7408ca1651613Montana State AGfiled 2018-11-13(14d gap)Candidate
- bd_8a74ba926b9e0e7fCalifornia State AGfiled 2018-11-13(14d gap)Verified
- bd_dcd4b744c7396396Washington State AGfiled 2018-11-13(14d gap)Verified by operator
- bd_f55c7eaa8530a3afOregon State AGfiled 2018-11-13(14d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-142122
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 27, 2018
- Raw hash
- 3f6d5128cadf8d402927b051854e4a581de9b21f5a4f7f79ad007e37894ed333
Reporting entity
- Name
- Synchrony Banknorm: synchrony bank
Victim entity
- Name
- STEIN MART, INC.norm: stein mart
Incident
- Discovered
- Jul 9, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.