CSIDB logo
Incident

Malley's Chocolates

Incident posture

Attack window
Apr 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-29 00:00

Linked entities

Victim
Malley's Chocolates
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack compromised the website of Malley’s Chocolates, exposing payment card details of approximately 3,400 online customers. The breach occurred during a peak sales period ahead of a major holiday, targeting transactions made through the company’s e-commerce platform while sparing in-store purchases at its physical locations. Stolen information included credit and debit card data, prompting the organization to notify impacted individuals via mailed communications shortly after discovering the incident. The compromise exclusively affected digital consumers, with no evidence suggesting broader system infiltration beyond the online payment environment.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Malley’s Chocolates data breach occurred approximately two weeks before Easter in 2018, with the intrusion targeting the company’s online payment systems. A hacker gained unauthorized access to the Brook Park-based confectioner’s website, compromising credit and debit card information belonging to 3,400 customers who had made purchases through the digital storefront. The breach exclusively affected transactions conducted via Malley’s online platform between late March and early April 2018, coinciding with the peak Easter holiday shopping period. Physical retail locations remained unaffected, as the attack vector specifically exploited vulnerabilities in the e-commerce infrastructure rather than point-of-sale systems across Malley’s 23 Northeast Ohio stores. The company detected anomalous activity prompting an internal investigation, though the exact timeline from intrusion discovery to confirmation remains unspecified in public disclosures.

Malley’s initiated customer notifications via physical mail during the week preceding May 10, 2018, advising impacted individuals of the card data exposure. The breach notification letters outlined the nature of the compromised information but did not specify whether additional personal identifiers like addresses or purchase histories were accessed. Company representatives emphasized that only online purchasers during the affected timeframe were at risk, excluding in-store customers and transactions processed outside the intrusion window. No details regarding forensic findings, attacker methodologies, or malware deployment were disclosed publicly. The incident caused operational disruptions during a critical sales period for the seasonal business, though Malley’s maintained regular store operations throughout the investigation. The company’s response focused on direct consumer outreach rather than public statements, with no subsequent disclosures about enhanced security measures or regulatory filings.

Sources

Sources available to members: 1 source.

CSIDB