Supply chain β›“ Supply Chain

Yves Rocher Third-Party Breach (September 2019)

πŸ“… 2019-09-01 🏒 Aliznet
Primary Source β†—

Incident Details

Cosmetics Giant Yves Rocher Caught in Data Leak Impacting Millions of Customers. International cosmetics brand Yves Rocher found itself caught in a third-party data exposure incident that leaked the personal information of millions of customers. Cosmetics giant Yves Rocher is warning that a giant data leak exposed the personal data of millions of its customers and reams of sensitive internal company information to the public. The data exposure stems from a database left unprotected by a third-party consultant to the firm. Third-party company: Aliznet.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Aliznet
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2019-09-01 Breach occurred
  2. 2019-09-03 Publicly disclosed