HackingData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
Bebe Stores, Inc.
bd_fe9a9d0054a6a10b · schema v1 · pii pii-v1
Full breach record for Bebe Stores, Inc. →Bebe Stores, Inc. detected suspicious activity on payment processing systems in its U.S., Puerto Rico, and U.S. Virgin Islands stores. The incident occurred between November 8 and November 26, 2014. Payment card data, including cardholder name, account number, expiration date, and verification code, may have been compromised. The company engaged a security firm, blocked the attack, and offered one year of credit monitoring to affected customers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-47667
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 5, 2014
- Raw hash
- ed694e6e413473704c6bb20ec07faa029221d898a37d2417d3d8f0baf35acf5a
Reporting entity
- Name
- Bebe Stores, Inc.norm: bebe stores
- Domain
- www.bebe.com
Victim entity
- Name
- Bebe Stores, Inc.norm: bebe stores
- Domain
- www.bebe.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney General
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.