CSIDB logo
Incident

Yandy

Incident posture

Attack window
May 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-19 10:10

Linked entities

Victim
Yandy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach at Yandy.com compromised customer financial data during checkout, exposing payment card numbers, expiration dates, CVV codes, and email addresses. Unauthorized access occurred during a multi-month period before detection, prompting immediate corrective actions to secure the site; the company did not confirm misuse of the stolen information or disclose the exact number of affected individuals, though its substantial social media following suggests a potentially large customer base. The incident impacted sensitive personal information submitted through the online retailer's platform.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In 2014, Yandy.com, an online retailer specializing in women's lingerie and clothing, experienced a security breach that compromised customer financial data. Between May 28 and August 18 of that year, an unidentified attacker gained unauthorized access to the company's database on four separate occasions. The breached database contained sensitive payment card information submitted by customers during the checkout process. Exposed data included credit and debit card numbers, expiration dates, CVV security codes, and associated email addresses. Company administrators detected the intrusion on August 18, though the article does not specify the detection method or initial attack vector. Following discovery, Yandy.com implemented corrective measures to address the vulnerability and restore system integrity. The Phoenix-based retailer, which had operated since 2005 and offered over 10,000 products, did not publicly disclose how many customers were affected by the breach.

Yandy.com responded to the incident by notifying affected customers through direct letters that outlined the nature of the data exposure. These communications advised recipients to monitor their financial accounts for signs of identity theft or fraudulent activity. The company acknowledged it could not determine whether the stolen information had been misused following the breach. While Yandy.com refrained from publishing exact victim counts, its substantial online presence—including thousands of social media followers across Twitter and Instagram, plus over 720,000 Facebook page likes—suggested a potentially wide impact. The breach exclusively targeted payment information processed through the website's checkout system during the nearly three-month intrusion period. No additional compromised data types or subsequent attacker activities beyond the four database accesses were reported in the available information.

Sources

Sources available to members: 1 source.

CSIDB