DisclosureLens
MalwareTechnologyRetail & ConsumerInformationInfostealerIistealerSupply Chain (3P Vendor)Customer Data InvolvedFinancial accountFinancial credentialsIdentity (basic)MediumContained

Joissu, Inc.

bd_2b5f92cf087c848b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 1, 2022

Filed

Sep 1, 2022

To disclose

30 weeks

Affected

4,264

Confidence

66%
Full breach record for Joissu, Inc.2 incidents on file

Freestyle Solutions, Inc., a third-party vendor providing shopping cart and payment processing services to Joissu, Inc., experienced a data security breach involving IIStealer malware on its servers. The malware captured payment card information (card number, expiration date, security code) and identity data (name, billing address) of 4,264 individuals who used cards on Joissu's site between September 2020 and February 3, 2022. Freestyle discovered the malware in early February 2022, removed it, and engaged forensic experts. Joissu is terminating its relationship with Freestyle and transitioning to a new vendor.

Incident timeline

undetected · 518 days
discovery → filing · 30 weeks / 212 days

Sep 1, 2020

Begins

Feb 1, 2022

Discovered

Sep 1, 2022

Filed

vs. sector median

+18 wks slower

Part of FreeStyle Solutions supply-chain incident (2022) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,264 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.