HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
FabFitFun
bd_1958392dde882750 · schema v1 · pii pii-v1
Full breach record for FabFitFun →FabFitFun, Inc. disclosed a data breach affecting customers who signed up between April 26, 2020, and August 3, 2020. An unauthorized third party inserted malicious code on the website's new member sign-up pages, potentially capturing emails, passwords, and payment card details (including CVV and expiration dates) for credit/debit card users. The company engaged forensic experts, removed the malicious code, reset passwords, and offered one year of complimentary identity protection services.
California clockDiscovered May 14, 2020 → Notified Aug 3, 202081d ✗ CA 60-day late18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3846524d2498eaedOregon State AGfiled 2020-09-18Candidate
- bd_856ea1b4b51736acWashington State AGfiled 2020-09-18Verified
- bd_ff5db961d83e67fbMaine State AGfiled 2020-09-18Verified
- bd_50163f839ce68266Delaware State AGfiled 2020-09-15(3d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 4d gap
- bd_9ad0328ed2f0b6d0Montana State AGfiled 2020-09-22(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194225
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 18, 2020
- Raw hash
- b1735ef824d29f529a2881eaf911a0da444193c4351ed0c42b33e86b30ba67a1
Reporting entity
- Name
- FabFitFunnorm: fabfitfun
Victim entity
- Name
- FabFitFunnorm: fabfitfun
Incident
- Discovered
- May 14, 2020
- Materiality determined
- —
- Notification sent
- Aug 3, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- reported the matter to law enforcement and are cooperating with the investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- CA 60-day late · 81d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 14, 2020→ Notified: Aug 3, 202081d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.