Skip to content
NetarxImpact Database
Credential Phishing PortalNo AI reportedConfirmed

Bed Bath & Beyond discloses data breach to SEC after an employee was phished

Bed Bath & Beyond · Retail · United States · October 2022

What happened

Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.

How the deception worked

A single employee at the retailer was targeted with a phishing message and fell for it, handing the attacker access to that employee's account. What followed illustrates why one employee's compromise is rarely contained to one employee: the attacker reached not only files on the individual's own hard drive but also the shared network drives that the account had rights to open. Corporate shared drives accumulate years of departmental documents that no one has reviewed for sensitivity. The retailer disclosed the event as a material item to the SEC while investigation was still under way, and did not detail the phishing method used.

The control that would have caught it· our reading, not a claim from the sources

Least-privilege access to shared drives and periodic review of what accumulates on them decide how much one phished account is actually worth.

Sources (2)

  1. Bed, Bath & Beyond confirms data breach following employee phishing attack
    TechCrunch·techcrunch.comOpen ↗
  2. Bed Bath & Beyond Investigating Data Breach After Employee Falls for Phishing Attack
    SecurityWeek·securityweek.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.