DisclosureLens
MalwareRetail & ConsumerRetailRansomwareCapture Stored DataData ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Financial accountAuthenticationLowContained

MUJI U.S.A. LIMITED

bd_3161c832f0747ad6 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Nov 30, 2015

To disclose

Affected

664state residents only

Linked

2 filings

Confidence

69%

MUJI U.S.A. LIMITED reported a cyberattack where malware infiltrated its online server, potentially exposing customer PII including names, addresses, and credit card details (number, expiration, CVV) for orders placed between Jan 22 and July 20, 2015. Approximately 664 Washington residents were affected. The company shut down its site, engaged forensic specialists, eliminated the malware, and offered credit monitoring.

Incident timeline

Jan 22, 2015

Begins

Nov 30, 2015

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Washington State AGNov 30 · first · this page

Pattern: first filing Nov 30 (WA), last Dec 7 (MA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.