DisclosureLens
HackingRetail & ConsumerRetailData ExfiltratedCustomer Data InvolvedPCIFinancial accountFinancial credentialsIdentity (basic)LowContained

Bebe Stores, Inc.

bd_fe9a9d0054a6a10b · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Dec 5, 2014

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for Bebe Stores, Inc.2 incidents on file

Bebe Stores, Inc. detected suspicious activity on payment processing systems in its U.S., Puerto Rico, and U.S. Virgin Islands stores. The incident occurred between November 8 and November 26, 2014. Payment card data, including cardholder name, account number, expiration date, and verification code, may have been compromised. The company engaged a security firm, blocked the attack, and offered one year of credit monitoring to affected customers.

Incident timeline

Nov 8, 2014

Begins

Dec 5, 2014

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
California State AGDec 5 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.