Supply chain
β Supply Chain
Yves Rocher Third-Party Breach (September 2019)
Primary Source βIncident Details
Cosmetics Giant Yves Rocher Caught in Data Leak Impacting Millions of Customers. International cosmetics brand Yves Rocher found itself caught in a third-party data exposure incident that leaked the personal information of millions of customers. Cosmetics giant Yves Rocher is warning that a giant data leak exposed the personal data of millions of its customers and reams of sensitive internal company information to the public. The data exposure stems from a database left unprotected by a third-party consultant to the firm. Third-party company: Aliznet.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Aliznet
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2019-09-01 Breach occurred
- 2019-09-03 Publicly disclosed