HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSMediumContained
Loungefly LLC
bd_0e2d70abafef9180 · schema v1 · pii pii-v1
Full breach record for Loungefly LLC →Loungefly, LLC reported a data breach affecting its online store (loungefly.com) between September 19, 2018, and February 13, 2019. Unauthorized code was placed on the system operating the online store. The incident potentially exposed payment card data (names, account numbers, expiration dates, security codes) and customer usernames/passwords for fewer than 4,600 individuals. Loungefly secured the network, engaged law enforcement, and mandated password resets for all customers.
California clockDiscovered Feb 13, 2019 → Notified Jun 27, 2019134d ✗ CA 60-day late19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,600 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148443
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2019
- Raw hash
- 29ea4693ada8f52bf4d33aede57efde4830efec55703429ac34c75610718133b
Reporting entity
- Name
- Loungefly LLCnorm: loungefly
- Domain
- loungefly.com
Victim entity
- Name
- Loungefly LLCnorm: loungefly
- Domain
- loungefly.com
Incident
- Discovered
- Feb 13, 2019
- Materiality determined
- —
- Notification sent
- Jun 27, 2019
- Affected individuals
- 4,600
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported the matter to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- CA 60-day late · 134d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 13, 2019→ Notified: Jun 27, 2019134d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.