Bed, Bath and Beyond confirms another major data breach

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

American retail giant Bed, Bath & Beyond has suffered a data breach, the company has confirmed in an 8-K filing to the U.S. Securities and Exchange Commission (SEC), albeit with somewhat conflicting statements.

In its filing, the company said that it discovered a successful phishing attack against one of its employees. The unknown threat actor managed to access a hard drive, as well as some shared drives, to which the affected employee had access. 

But here is where it gets conflicting: In the same paragraph, the company says it’s analyzing the stolen data to see if there were any sensitive or personally identifiable information in the stolen batch, and that it has “no reason to believe” such data was accessed.

Details are scarce

In fact, even though the investigation is ongoing, Bed, Bath & Beyond says it has no reason to believe this event “would be likely to have a material impact” on the company. 

Other than this statement, the company provided no additional details. The media reached out to find out the amount and type of stolen data, to no avail. Furthermore, the company declined to comment if it has the technical means to even detect evidence of exfiltration, TechCrunch reported. 

This is not the first time the company has suffered a data breach. In fact, almost exactly three years ago (on October 29, 2019), the company also disclosed a data breach via an 8-K filing with the SEC.

Back then, it said it discovered a third party acquiring email and password information from a source “outside of the company’s systems”, which was subsequently used to access less than 1% of the company’s online customer accounts. While they did access sensitive information, the attackers did not get customer payment card information, it was confirmed. As a result, Bed, Bath & Beyond did not expect the data breach to result in any significant damages. 

Via: TechCrunch

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
Zagg warns customers their data may have been stolen in third-party cyberattack
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Suitcase next to a bed in a hotel
Millions of hotel users see personal info checked out in huge data leak
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
No broadband network
Massive online data breach sees 2.7 billion records leaked - here's what we know
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection