Bath & Body Works
ent_021b98f4619c3d1a11572d68
Disclosures
1
State AG · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
1
as filed · State AG MT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Bath & Body Works
- Normalized
- bath body works— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0000701985
- Domain
- None on record
Disclosure history (1)newest first
Subsidiary disclosures (7)filed by group companies
◈ These filings were made by or about subsidiaries of Bath & Body Works — not by Bath & Body Works itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- New Hampshire State AGvia Bath & Body Works Direct, Inc.2021-08-13
Bath & Body Works Direct, Inc. notified the NH AG that an unauthorized party accessed personal info in online loyalty accounts between June 20-25, 2021, likely via credential reuse from a third-party breach. 3 NH residents affected. Data included names, emails, addresses, phone numbers, loyalty numbers, and gift card details. BBW disabled passwords, coordinated with law enforcement, and offered 1 year of identity protection.
- Maine State AGvia Bath & Body Works Direct, Inc.2021-08-10
Bath & Body Works Direct, Inc. (BBW) reported a credential stuffing incident where an unauthorized party accessed online loyalty accounts between June 20 and June 25, 2021. The breach was discovered on June 23, 2021. The attacker likely used credentials stolen from another company's breach. The compromised information included names, email addresses, mailing addresses, birth day and month, phone numbers, loyalty account numbers, and linked gift card information. For customers who saved payment card details, only the last four digits were visible. In response, BBW secured the accounts, disabled passwords, and offered one year of free identity protection services to affected individuals.
- California State AGvia Bath & Body Works Direct, Inc.2021-08-10
Bath & Body Works Direct, Inc. reported that an unauthorized party accessed personal information in online loyalty accounts between June 20 and June 25, 2021. The breach resulted from credential reuse from a third-party system breach. Affected data included names, email addresses, mailing addresses, birth day/month, telephone numbers, loyalty account numbers, and gift card PINs. Only the last four digits of saved payment cards were visible. The company reset passwords, coordinated with law enforcement, and offered one year of identity protection.
- Massachusetts State AGvia Bath & Body Works Direct, Inc.2021-08-10
Bath & Body Works Direct, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-08-10. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGvia Bath & Body Works Direct, Inc.2021-08-10
Bath & Body Works Direct, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-06-20 and was reported on 2021-08-10. 268 Indiana residents were affected. 7,103 individuals affected in total.
- Illinois State AGvia Bath & Body Works Direct, Inc.2021-01-01
BATH & BODY WORKS DIRECT, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-323). The register records the breach as discovered on June 23, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGvia Bath & Body Works Direct, Inc.2019-12-23
Bath & Body Works Direct, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-12-23. 1 Massachusetts residents were affected. The report records the breach type as electronic.