Afaze
Incident posture
Timeline
Summary
Afaze and other retailers experienced a data security incident where malware collected payment card data from cards used in stores over several months. The compromised data included card numbers, expiration dates, CVVs, and in some cases names; the company removed the malware, worked with forensic experts, and confirmed the incident did not involve online transactions or PINs.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A & M (2015) LLC announced on November 11, 2016 that a data security incident may have compromised payment information for customers who used debit or credit cards at Annie Sez, Afaze, Mandee, Sirens and Urban Planet locations between November 24, 2015 and August 23, 2016. The company began investigating unusual activity after receiving reports from its credit card processor and engaged third‑party forensic experts to examine its systems. On August 11, 2016, investigators discovered suspicious files on the company’s computers that indicated a potential compromise of card data for some transactions at the affected stores. On August 23, 2016, A&M determined that those files were capable of collecting credit card information and immediately removed them from the environment.
The forensic investigation confirmed that malware may have stolen card data from some credit and debit cards used at U.S. locations of the five brands during the specified period. For cards used at all impacted locations except the Annie Sez store in Danbury, Connecticut and the Mandee store in Bergenfield, New Jersey, the exposed data included the card number, expiration date and CVV. For cards used at the Danbury Annie Sez location between October 15, 2015 and August 23, 2016 and the Bergenfield Mandee location between October 14, 2015 and August 23, 2016, the exposed data additionally included the cardholder’s name. The incident did not involve Social Security numbers, PIN numbers, or any online debit or credit card transactions conducted through the brands’ websites.
In response, A&M established a dedicated assistance line at 1‑844‑512‑9007 operating Monday through Friday from 9 a.m. to 9 p.m. EDT and posted incident details on the websites www.mandee.com and www.anniesez.com. The company continued to work with third‑party forensic investigators and law enforcement officials to determine the full scope of the breach and to ensure the security of its systems. After removing the malicious files, A&M implemented additional security procedures designed to prevent further unauthorized access to customer payment information.
Sources
Sources available to members: 1 source.