What happened
Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.
How the deception worked
A single employee at the retailer was targeted with a phishing message and fell for it, handing the attacker access to that employee's account. What followed illustrates why one employee's compromise is rarely contained to one employee: the attacker reached not only files on the individual's own hard drive but also the shared network drives that the account had rights to open. Corporate shared drives accumulate years of departmental documents that no one has reviewed for sensitivity. The retailer disclosed the event as a material item to the SEC while investigation was still under way, and did not detail the phishing method used.
The control that would have caught it· our reading, not a claim from the sources
Least-privilege access to shared drives and periodic review of what accumulates on them decide how much one phished account is actually worth.
Sources (2)
- Bed, Bath & Beyond confirms data breach following employee phishing attackTechCrunch·techcrunch.comOpen ↗
- Bed Bath & Beyond Investigating Data Breach After Employee Falls for Phishing AttackSecurityWeek·securityweek.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.