Bath & Body Works
ent_021b98f4619c3d1a11572d68
Disclosures
1
State AG · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
1
as filed · State AG MT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Bath & Body Works
- Normalized
- bath body works— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (1)newest first
Subsidiary disclosures (2)filed by group companies
◈ These filings were made by or about subsidiaries of Bath & Body Works — not by Bath & Body Works itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🦞Maine State AGvia Bath & Body Works Direct, Inc.2021-08-10
Bath & Body Works Direct, Inc. (BBW) reported a credential stuffing incident where an unauthorized party accessed online loyalty accounts between June 20 and June 25, 2021. The breach was discovered on June 23, 2021. The attacker likely used credentials stolen from another company's breach. The compromised information included names, email addresses, mailing addresses, birth day and month, phone numbers, loyalty account numbers, and linked gift card information. For customers who saved payment card details, only the last four digits were visible. In response, BBW secured the accounts, disabled passwords, and offered one year of free identity protection services to affected individuals.
- 🐻California State AGvia Bath & Body Works Direct, Inc.2021-08-10
Bath & Body Works Direct, Inc. disclosed a cybersecurity incident affecting online loyalty accounts between June 20 and June 25, 2021. An unauthorized party accessed data by exploiting credentials stolen from a third-party breach. Affected data included names, emails, addresses, phone numbers, loyalty numbers, and partial payment card digits. The company disabled passwords, coordinated with law enforcement, and offered one year of free identity protection services.