David's Bridal notified customers and staff of January 2024 data breach
- Organization
- David's Bridal
- Exploit
- Hacking
- Industry
- Retail
David's Bridal, the US wedding attire retailer, began notifying employees and customers in September 2024 that their personal information had been exposed in an intrusion dating back to January 2024. The company filed a breach notice with the Maine Attorney General's Office on September 13, 2024, reporting that it had detected unusual activity on its network on January 21, 2024, secured its systems, retained outside investigators and contacted federal law enforcement.
The investigation concluded that files containing personal information were accessed without authorization on or around January 20, 2024. The Maine filing listed names and Social Security numbers, and stated that consumer payment card information was not involved. A parallel report filed in Texas described a broader set of data, including addresses, driver's license numbers, medical information and health insurance information, and covered at least 4,132 Texas residents. David's Bridal did not publish a nationwide total.
Two ransomware groups had separately claimed to have breached the retailer earlier in the year. LockBit listed David's Bridal in January 2024 and Werewolves followed in February 2024, with Comparitech reporting a demand of $850,000 from the latter group. David's Bridal did not confirm either claim, and did not say whether any ransom was paid.
By late September 2024 the company was facing at least two proposed class actions alleging inadequate security and an eight month gap between the intrusion and notification.