Best Buy Co., Inc.
ent_019e5be291744846fb28ffd8cbe9410c
Disclosures
11
State AG · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
10,414
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Best Buy Co., Inc.
- Normalized
- best buy— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- HL5XPTVRV0O8TUN5LL90
- SEC EDGAR CIK
- 0000764478
- Domain
- None on record
Disclosure history (11)newest first
- Indiana State AGas victim2022-11-08
Best Buy Stores, LP reported a data breach to the Indiana Attorney General. The breach occurred on 2021-02-24 and was reported on 2022-11-08. 1 Indiana residents were affected. 15 individuals affected in total.
- Massachusetts State AGas victim2022-11-08
Best Buy Stores, LP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-11-08. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2018-04-25
Best Buy Co.,Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2018-04-25. The breach occurred during 9/26/2017 - 10/12/2017. Notice was sent on 4/13/2018.
- South Carolina State AGas victim2018-04-17
Best Buy notified customers of a data breach involving third-party vendor [24]7.ai. Malicious code inserted in vendor software between Sept 26 and Oct 12, 2017, allowed unauthorized access to payment card data (names, addresses, card numbers, CVV) for customers shopping on BestBuy.com during that period. Best Buy engaged forensic experts, removed the code, and offered 1 year of credit monitoring via Identity Guard.
- Washington State AGas victim2018-04-13
Best Buy Co, Inc. reported a data breach affecting Washington residents due to a cyber intrusion of third-party vendor [24]7.ai. Malicious code inserted between Sept 26 and Oct 12, 2017, allowed unauthorized access to customer payment card info and PII. Best Buy discovered the issue in March 2018, engaged forensic experts, and provided 1 year of credit monitoring to affected individuals.
- Massachusetts State AGas victim2018-04-13
Best Buy Co., Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-13. 10,414 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2018-04-13
Best Buy Co., Inc. notified customers that a third-party vendor, [24]7.ai, suffered a cyber intrusion in which malicious code was inserted into its customer service chat software between September 26 and October 12, 2017. The code enabled unauthorized access to payment card information (name, address, card number, expiration date, security code) of BestBuy.com customers. Best Buy publicly disclosed on April 5, 2018 and sent consumer notifications April 12, 2018. Identity Guard credit monitoring offered to affected individuals.
- New Hampshire State AGas victim2018-04-13
Best Buy Co., Inc. notified the NH AG of a data breach involving third-party vendor [24]7.ai. Malicious code inserted between Sept 26 and Oct 12, 2017, allowed unauthorized access to customer payment card info (names, addresses, card numbers, CVV) for shoppers on BestBuy.com during that window. Best Buy engaged forensic experts, removed the code, and changed software operations. No count of affected individuals was provided.
- Montana State AGas victim2018-04-12
Best Buy Co., Inc. notified Montana residents of a data breach involving third-party vendor [24]7.ai. Malicious code inserted in vendor software between Sept 26 and Oct 12, 2017, allowed unauthorized access to customer payment card data (names, addresses, card numbers, CVV) for BestBuy.com shoppers during that period. Best Buy engaged forensic experts, removed the code, and offered one year of Identity Guard credit monitoring.
- Massachusetts State AGas victim2017-07-11
Best Buy Co., Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-11. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2009-02-02
Best Buy notified New Hampshire of a credit card skimming incident at a West Palm Beach, FL store. An employee used a handheld skimmer to steal card info in Nov-Dec 2008. Best Buy discovered the incident on Jan 5, 2009, and notified the Secret Service. One NH resident was affected. Best Buy provided one year of credit monitoring.
Supply-chain cascadesreviewed and confirmed
- Best Buy Co., Inc.’s filing is one of at least 5 in the [24]7.ai supply-chain incident (2018).