CSIDB logo
Incident

Afaze

Incident posture

Attack window
Oct 2015
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-05 10:49

Linked entities

Victim
Afaze
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Afaze and other retailers experienced a data security incident where malware collected payment card data from cards used in stores over several months. The compromised data included card numbers, expiration dates, CVVs, and in some cases names; the company removed the malware, worked with forensic experts, and confirmed the incident did not involve online transactions or PINs.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A & M (2015) LLC announced on November 11, 2016 that a data security incident may have compromised payment information for customers who used debit or credit cards at Annie Sez, Afaze, Mandee, Sirens and Urban Planet locations between November 24, 2015 and August 23, 2016. The company began investigating unusual activity after receiving reports from its credit card processor and engaged third‑party forensic experts to examine its systems. On August 11, 2016, investigators discovered suspicious files on the company’s computers that indicated a potential compromise of card data for some transactions at the affected stores. On August 23, 2016, A&M determined that those files were capable of collecting credit card information and immediately removed them from the environment.

The forensic investigation confirmed that malware may have stolen card data from some credit and debit cards used at U.S. locations of the five brands during the specified period. For cards used at all impacted locations except the Annie Sez store in Danbury, Connecticut and the Mandee store in Bergenfield, New Jersey, the exposed data included the card number, expiration date and CVV. For cards used at the Danbury Annie Sez location between October 15, 2015 and August 23, 2016 and the Bergenfield Mandee location between October 14, 2015 and August 23, 2016, the exposed data additionally included the cardholder’s name. The incident did not involve Social Security numbers, PIN numbers, or any online debit or credit card transactions conducted through the brands’ websites.

In response, A&M established a dedicated assistance line at 1‑844‑512‑9007 operating Monday through Friday from 9 a.m. to 9 p.m. EDT and posted incident details on the websites www.mandee.com and www.anniesez.com. The company continued to work with third‑party forensic investigators and law enforcement officials to determine the full scope of the breach and to ensure the security of its systems. After removing the malicious files, A&M implemented additional security procedures designed to prevent further unauthorized access to customer payment information.

Sources

Sources available to members: 1 source.

CSIDB