Plant Therapy
bd_0867b7e481b0e6ce · schema v1 · pii pii-v1
Full breach record for Plant Therapy →Plant Therapy disclosed a data breach affecting approximately 1,074 California residents. On May 11, 2018, the company learned of unauthorized malware installation on its third-party e-commerce platform. The incident potentially exposed payment card information (names, card numbers, expiration dates, security codes) for customers who made purchases between March 29, 2018, and May 11, 2018. Plant Therapy engaged a forensic firm, notified the FBI and payment card brands, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 29, 2018
Begins
May 11, 2018
Discovered
Jul 30, 2018
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_3cd75aae86e56baf2018-07-30Candidate
- Massachusetts State AGbd_3d9d3abb5faf53fb2018-07-30Verified
- New Hampshire State AGbd_bc629abe00f8818d2018-07-30Verified
- Massachusetts State AGbd_be1320f2bb0919c42018-09-21 · +53dVerified by operator
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Jul 30 (MT), last Sep 21 (MA) — a 53-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.