An attacker gained unauthorized access to customer information on BaileysOnline.com. and stole payment card information of 250K customers.
The compromised data included the Credit card numbers, cardholder names, CCV numbers, credit card expiration dates, addresses and phone numbers, email addresses, log in credentials to BaileysOnline.com, and other information typed into the website related to customer orders.
The company informed various law enforcement agencies as well as Wells Fargo Bank, MasterCard, Visa, American Express and Discover.
They investigated the incident and took preventive steps to enhance the security and replaced its servers, enhanced its firewalls, integrated mandatory changes with respect to passwords, and integrated new software into the website.
TPRM report: https://scoringcyber.rankiteo.com/company/bailey's-inc.
"id": "bai232817522",
"linkid": "bailey's-inc.",
"type": "Breach",
"date": "03/2016",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of a geographical region"
{'affected_entities': [{'customers_affected': '250K',
'industry': 'Retail',
'name': 'BaileysOnline.com',
'type': 'E-commerce'}],
'attack_vector': 'Unauthorized Access',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '250K',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Credit card numbers',
'Cardholder names',
'CCV numbers',
'Credit card expiration dates',
'Addresses and phone numbers',
'Email addresses',
'Log in credentials to '
'BaileysOnline.com',
'Other information related to '
'customer orders']},
'description': 'An attacker gained unauthorized access to customer '
'information on BaileysOnline.com and stole payment card '
'information of 250K customers.',
'impact': {'data_compromised': ['Credit card numbers',
'Cardholder names',
'CCV numbers',
'Credit card expiration dates',
'Addresses and phone numbers',
'Email addresses',
'Log in credentials to BaileysOnline.com',
'Other information related to customer '
'orders'],
'payment_information_risk': 'High'},
'motivation': 'Data Theft',
'references': [{'source': 'BaileysOnline.com Data Breach Report'}],
'response': {'law_enforcement_notified': 'Yes',
'remediation_measures': ['Replaced its servers',
'Enhanced its firewalls',
'Integrated mandatory changes with '
'respect to passwords',
'Integrated new software into the '
'website']},
'threat_actor': 'Unknown',
'title': 'BaileysOnline.com Data Breach',
'type': 'Data Breach'}