HackingStolen CredentialsTargetedPCIFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
VERA BRADLEY, INC.
bd_f91573fcce9830f7 · schema v1 · pii pii-v1
Full breach record for VERA BRADLEY, INC. →Vera Bradley, Inc. notified customers of a data breach affecting payment card data used at retail stores between July 25, 2016 and September 23, 2016. Unauthorized access to the payment processing system led to the installation of malware designed to capture magnetic stripe track data. The incident was discovered on September 15, 2016, following law enforcement notification. Vera Bradley engaged a computer security firm, stopped the incident, and notified payment card networks. No other customer information was at risk. The number of affected individuals was not disclosed.
California clockDiscovered Sep 15, 2016 → Notified Oct 12, 201627d ✓ CA 60-day OK27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64353
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 12, 2016
- Raw hash
- da128bfd5e88eaae551bcb33f8a3643126cc74337a4ae6eea26625ccdc048cc0
Reporting entity
- Name
- VERA BRADLEY, INC.norm: vera bradley
- Domain
- verabradley.com
Victim entity
- Name
- VERA BRADLEY, INC.norm: vera bradley
- Domain
- verabradley.com
Incident
- Discovered
- Sep 15, 2016
- Materiality determined
- Oct 12, 2016
- Notification sent
- Oct 12, 2016
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided information from law enforcement regarding a potential data security issue
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 27d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 15, 2016→ Notified: Oct 12, 201627d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.