Spiraledge, Inc.
bd_3542cadf5740d1a7 · schema v1 · pii pii-v1
Full breach record for Spiraledge, Inc. →Spiraledge, Inc. (operator of SwimOutlet.com and YogaOutlet.com) experienced a sophisticated cyber-attack compromising customer payment data. The breach occurred between May 2 and November 22, 2016. Unusual activity was detected on October 31, 2016, and the attack was confirmed on November 28, 2016. Affected data includes cardholder names, addresses, phone numbers, email addresses, card numbers, expiration dates, and CVVs. The company engaged forensic experts and the FBI, removed malicious software, and implemented additional security procedures.
J jump to incidentP pin to compareR raw source
Incident timeline
May 2, 2016
Begins
Oct 31, 2016
Discovered
Jan 12, 2017
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Oregon State AGbd_6cc466ec946530612017-01-12Candidate
- Massachusetts State AGbd_869a6fc8b3a3e5b92017-01-12Verified
- Washington State AGbd_a7ef1cdcd01a568f2017-01-12Verified
- Hawaii State AGbd_04680317a3d78f602017-01-19 · +7dVerified
Show 1 more filing ↓Show fewer ↑up to 8d gap
- New Hampshire State AGbd_8cd5f5eb95f5137d2017-01-20 · +8dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jan 12 (OR), last Jan 20 (NH) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.