MalwareRansomwareData EncryptedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Manduka
bd_197f9054f6cba465 · schema v1 · pii pii-v1
Full breach record for Manduka →Manduka reported a data security incident involving unauthorized malware installation on its e-commerce platform. The incident affected payment card information (names, card numbers, expiration dates, security codes) of customers who used the platform between February 22, 2017, and May 20, 2018. Manduka notified 9,616 California residents, engaged forensic investigators, and reported the incident to the FBI and Secret Service. Remediation included removing malware, implementing MFA, and rebuilding the e-commerce site.
California clockDiscovered Feb 25, 2018 → Notified Mar 26, 201829d ✓ CA 60-day OK15 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_459f89eec1979764Washington State AGfiled 2018-03-27(73d gap)Verified
- bd_5ecb4e4d561a06bfOregon State AGfiled 2018-03-27(73d gap)Verified
- bd_7ff02f57c5673209California State AGfiled 2018-03-27(73d gap)Verified
- bd_900e824b2ddbde8dMontana State AGfiled 2018-03-26(74d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136968
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 8, 2018
- Raw hash
- f7e74d481a10efb84b76ddae1d179ca0b63279c520f8d75bced73da0cb26c805
Reporting entity
- Name
- Mandukanorm: manduka
Victim entity
- Name
- Mandukanorm: manduka
Incident
- Discovered
- Feb 25, 2018
- Materiality determined
- —
- Notification sent
- Mar 26, 2018
- Affected individuals
- 9,651
- Data types
- PCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney General Xavier Becerra
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(103 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 25, 2018→ Notified: Mar 26, 201829d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.