Supply chain ⛓ Supply Chain

UNIQLO Third-Party Breach (May 2019)

📅 2019-05-01 🏢 not
Primary Source ↗

Incident Details

Cyber-attack affects over 460,000 online store accounts. The compromised information included, customer name, address, phone number, email address, gender, date of birth, purchase history, clothing measurements, credit card information. The popular online stores in Japan, UNIQLO Japan and GU Japan, recently revealed that it suffered a cyber-attack that affected more than 460,000 of its customers. Fast Retailing , the parent company behind the UNIQLO Japan and GU Japan online stores, stated the unknown hackers allegedly accessed its customers’ accounts from April 23, 2019, to May 10, 2019, following a credential stuffing attack. According to Fast Retailing, the compromised information included, customer name, address, phone number, email address, gender, date of birth, purchase history, clothing measurements, and credit card information. Third-party company: not.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
not
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2019-05-01 Breach occurred
  2. 2019-05-16 Publicly disclosed