Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICFINANCIALLowContained
COTY INC.
bd_ffa8a6399c145ac2 · schema v1 · pii pii-v1
Full breach record for COTY INC. →Coty, Inc. disclosed that hackers used phishing techniques to access employee email accounts in January and February 2018. The company became aware of the incident on January 12, 2018. The attackers primarily targeted corporate financial information, but personal details of customers and employees may have been exposed. Coty contained the incident, reset passwords, enhanced email security processes, and engaged forensic experts. Credit monitoring services were offered to affected individuals.
California clockDiscovered Jan 12, 2018 → Notified Jul 1, 2018170d ✗ CA 60-day late25 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_42a674d07db4cdb1Montana State AGfiled 2018-07-06Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-137727
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 6, 2018
- Raw hash
- c0826eafbada7c40c92590ff3b9e5d29654c7104211b0373e63395cc866e4b4f
Reporting entity
- Name
- COTY INC.norm: coty
- Domain
- coty.com
Victim entity
- Name
- COTY INC.norm: coty
- Domain
- coty.com
Incident
- Discovered
- Jan 12, 2018
- Materiality determined
- —
- Notification sent
- Jul 1, 2018
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email CollectionT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to law enforcement in the United States both at the federal and state levels
- Initial access
- phishing_link
Compliance
- Time to disclose
- 25 weeks(175 days from discovery to filing)
- Compliance flags
- CA 60-day late · 170d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 12, 2018→ Notified: Jul 1, 2018170d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.