Bath & Body Works Direct, Inc.
ent_cd2eca8de2d28588470605a4
Disclosures
7
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
7,103
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Bath & Body Works Direct, Inc.
- Normalized
- bath body works direct— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Bath & Body Works— per SEC Exhibit 21 filing
Disclosure history (7)newest first
- New Hampshire State AGas victim2021-08-13
Bath & Body Works Direct, Inc. notified the NH AG that an unauthorized party accessed personal info in online loyalty accounts between June 20-25, 2021, likely via credential reuse from a third-party breach. 3 NH residents affected. Data included names, emails, addresses, phone numbers, loyalty numbers, and gift card details. BBW disabled passwords, coordinated with law enforcement, and offered 1 year of identity protection.
- Maine State AGas victim2021-08-10
Bath & Body Works Direct, Inc. (BBW) reported a credential stuffing incident where an unauthorized party accessed online loyalty accounts between June 20 and June 25, 2021. The breach was discovered on June 23, 2021. The attacker likely used credentials stolen from another company's breach. The compromised information included names, email addresses, mailing addresses, birth day and month, phone numbers, loyalty account numbers, and linked gift card information. For customers who saved payment card details, only the last four digits were visible. In response, BBW secured the accounts, disabled passwords, and offered one year of free identity protection services to affected individuals.
- California State AGas victim2021-08-10
Bath & Body Works Direct, Inc. reported that an unauthorized party accessed personal information in online loyalty accounts between June 20 and June 25, 2021. The breach resulted from credential reuse from a third-party system breach. Affected data included names, email addresses, mailing addresses, birth day/month, telephone numbers, loyalty account numbers, and gift card PINs. Only the last four digits of saved payment cards were visible. The company reset passwords, coordinated with law enforcement, and offered one year of identity protection.
- Massachusetts State AGas victim2021-08-10
Bath & Body Works Direct, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-08-10. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2021-08-10
Bath & Body Works Direct, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-06-20 and was reported on 2021-08-10. 268 Indiana residents were affected. 7,103 individuals affected in total.
- Illinois State AGas victim2021-01-01
BATH & BODY WORKS DIRECT, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-323). The register records the breach as discovered on June 23, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2019-12-23
Bath & Body Works Direct, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-12-23. 1 Massachusetts residents were affected. The report records the breach type as electronic.