Menu
Browse

Cyber Incident Victim: EyeBuyDirect

Date:

Feb 2015

Location:

Russia

Summary

EyeBuyDirect experienced unauthorized website access potentially compromising customer names, addresses, phone numbers, email addresses, and payment card details including credit card numbers and CVV codes. The intrusion originated from a Russian IP address over several months before being discovered; the company disabled the attackers' access, implemented enhanced security measures, notified affected individuals, and provided complimentary identity theft protection for one year.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Unauthorized access to EyeBuyDirect’s website occurred between February 9 and May 30, 2015, with attackers operating from a Russian IP address compromising customer data. The breach exposed personally identifiable information and payment card details, including names, mailing addresses, shipping addresses, phone numbers, email addresses, credit card numbers, and CVV security codes. EyeBuyDirect discovered the intrusion on June 16, 2015, though the exact number of affected individuals remains undisclosed. Forensic investigators were engaged to assess the incident, concluding their analysis with a final report delivered to the company on September 22, 2015. The attackers’ access pathway and specific exploitation methods within the website infrastructure were not detailed in public disclosures.

Cyber Incident Image

Upon confirming the breach, EyeBuyDirect terminated the attackers’ access and implemented additional security measures to prevent recurrence. The company began notifying potentially affected customers by October 13, 2015, offering a complimentary year of identity theft protection services. No evidence suggested misuse of exposed payment card data at the time of disclosure. The incident prompted operational adjustments to reduce future vulnerabilities, though technical specifics of these enhancements were not publicly documented. New Hampshire’s Department of Justice published an official breach notification coinciding with customer outreach efforts, confirming the compromise timeline and data types involved.

Sources
Sources available to members
1 source