Bath & Body Works Direct, Inc.
ent_cd2eca8de2d28588470605a4
Disclosures
2
State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Bath & Body Works Direct, Inc.
- Normalized
- bath body works direct— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Bath & Body Works— per SEC Exhibit 21 filing
Disclosure history (2)newest first
- 🦞Maine State AGas victim2021-08-10
Bath & Body Works Direct, Inc. (BBW) reported a credential stuffing incident where an unauthorized party accessed online loyalty accounts between June 20 and June 25, 2021. The breach was discovered on June 23, 2021. The attacker likely used credentials stolen from another company's breach. The compromised information included names, email addresses, mailing addresses, birth day and month, phone numbers, loyalty account numbers, and linked gift card information. For customers who saved payment card details, only the last four digits were visible. In response, BBW secured the accounts, disabled passwords, and offered one year of free identity protection services to affected individuals.
- 🐻California State AGas victim2021-08-10
Bath & Body Works Direct, Inc. disclosed a cybersecurity incident affecting online loyalty accounts between June 20 and June 25, 2021. An unauthorized party accessed data by exploiting credentials stolen from a third-party breach. Affected data included names, emails, addresses, phone numbers, loyalty numbers, and partial payment card digits. The company disabled passwords, coordinated with law enforcement, and offered one year of free identity protection services.