Spiraledge, Inc.
bd_04680317a3d78f60 · schema v1 · pii pii-v1
Full breach record for Spiraledge, Inc. →Spiraledge, Inc. notified the Hawaii Office of Consumer Protection of a cyber-attack affecting its e-commerce sites (SwimOutlet.com, YogaOutlet.com). Unauthorized access occurred between May 2, 2016, and November 22, 2016, compromising payment card data (name, address, card number, CVV) for 1,823 Hawaii residents. The incident was discovered on October 31, 2016, following unusual activity reported by a credit card processor. Spiraledge engaged forensic investigators and the FBI, removed malware, and notified affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 2, 2016
Begins
Oct 31, 2016
Discovered
Jan 19, 2017
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- New Hampshire State AGbd_8cd5f5eb95f5137d2017-01-20 · +1dVerified
- California State AGbd_3542cadf5740d1a72017-01-12 · +7dVerified
- Oregon State AGbd_6cc466ec946530612017-01-12 · +7dCandidate
- Massachusetts State AGbd_869a6fc8b3a3e5b92017-01-12 · +7dVerified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- Washington State AGbd_a7ef1cdcd01a568f2017-01-12 · +7dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jan 12 (CA), last Jan 20 (NH) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.