Bath & Body Works Direct, Inc. (BBW) reported a credential stuffing incident where an unauthorized party accessed online loyalty accounts between June 20 and June 25, 2021. The breach was discovered on June 23, 2021. The attacker likely used credentials stolen from another company's breach. The compromised information included names, email addresses, mailing addresses, birth day and month, phone numbers, loyalty account numbers, and linked gift card information. For customers who saved payment card details, only the last four digits were visible. In response, BBW secured the accounts, disabled passwords, and offered one year of free identity protection services to affected individuals.
Affected (this filing): 1