CSIDB logo
Incident

My Intimacy

Incident posture

Attack window
May 2015
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-15 16:05

Linked entities

Victim
My Intimacy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A lingerie retailer experienced a compromise of its ecommerce server, potentially exposing customer names, credit card numbers, expiration dates, and verification codes. The breach involved unauthorized code insertion on the server, affecting U.S. customers who interacted with the online store over a multi-month period. Law enforcement assisted the ongoing investigation, while the company implemented security enhancements and notified all potentially impacted individuals. Affected customers were offered complimentary identity theft protection and credit monitoring services for one year.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Intimacy Bra Fit Stylists discovered on May 5, 2015, that its ecommerce server had been compromised, potentially exposing customer data. An investigation determined that unauthorized code had been inserted into the server infrastructure. The breach impacted U.S. customers who placed or attempted to place orders through myintimacy.com between December 15, 2014, and April 30, 2015. Compromised information included full names, credit card numbers, associated expiration dates, and card verification values (CVVs). The company did not disclose the exact number of affected individuals. Forensic analysis confirmed that attackers gained sufficient access to misappropriate personal information during the four-and-a-half-month exposure window. The intrusion specifically targeted transactional data processed through the online sales platform.

Law enforcement agencies assisted Intimacy in conducting an ongoing investigation following the breach discovery. The company implemented security enhancements to its policies, procedures, and technical safeguards to prevent recurrence. All potentially affected customers received direct notification about the incident and its potential consequences. Intimacy offered impacted individuals complimentary identity theft protection services and credit monitoring coverage for twelve months at no cost. The New Hampshire Department of Justice published the organization's security breach notification letter on June 4, 2015, confirming these remediation measures. No additional technical details regarding the attack methodology or threat actor attribution were disclosed in public filings. The incident exclusively affected customers engaged with the ecommerce platform during the specified timeframe, with no evidence suggesting compromise of physical retail locations or other business operations.

Sources

Sources available to members: 1 source.

CSIDB