HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Rea.deeming Beauty, Inc.
bd_feb940a4e809449e · schema v1 · pii pii-v1
Full breach record for Rea.deeming Beauty, Inc. →Rea.deeming Beauty Inc. d/b/a beautyblender disclosed a data security incident where malware on its website collected customer payment card information (name, address, full credit card number, expiration, CVV). The malware was present between April 23, 2015, and October 26, 2017. 3,673 California residents were notified. The company removed the malware and implemented additional security measures.
California clockDiscovered Oct 26, 2017 → Notified Jan 5, 201871d ✗ CA 60-day late10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e3dab93b8771c61aOregon State AGfiled 2018-01-05Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-132088
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 5, 2018
- Raw hash
- 723bfc707743cabb021ecb18964e5a988f90c3ab781b8ed80a1291dafa619e7e
Reporting entity
- Name
- Rea.deeming Beauty, Inc.norm: readeeming beauty
Victim entity
- Name
- Rea.deeming Beauty, Inc.norm: readeeming beauty
Incident
- Discovered
- Oct 26, 2017
- Materiality determined
- —
- Notification sent
- Jan 5, 2018
- Affected individuals
- 3,673
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified required state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- CA 60-day late · 71d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 26, 2017→ Notified: Jan 5, 201871d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.