MUJI U.S.A. LIMITED
bd_3161c832f0747ad6 · schema v1 · pii pii-v1
MUJI U.S.A. LIMITED reported a cyberattack where malware infiltrated its online server, potentially exposing customer PII including names, addresses, and credit card details (number, expiration, CVV) for orders placed between Jan 22 and July 20, 2015. Approximately 664 Washington residents were affected. The company shut down its site, engaged forensic specialists, eliminated the malware, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 22, 2015
Begins
Nov 30, 2015
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_8cfbc4cd060e3aef2015-12-07 · +7dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Nov 30 (WA), last Dec 7 (MA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.