HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Spiraledge, Inc.
bd_3542cadf5740d1a7 · schema v1 · pii pii-v1
Full breach record for Spiraledge, Inc. →Spiraledge, Inc. disclosed a cyber-attack affecting SwimOutlet.com and YogaOutlet.com. The breach occurred between May 2, 2016, and November 22, 2016. Customer payment card data, including names, addresses, card numbers, and CVVs, was compromised. Spiraledge engaged forensic experts and the FBI, removed malicious software, and notified affected customers in January 2017.
California clockDiscovered Oct 31, 2016 → Notified Jan 12, 201773d ✗ CA 60-day late10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6cc466ec94653061Oregon State AGfiled 2017-01-12Candidate
- bd_a7ef1cdcd01a568fWashington State AGfiled 2017-01-12Verified
- bd_04680317a3d78f60Hawaii State AGfiled 2017-01-19(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65809
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2017
- Raw hash
- c86b90e7819f93b21c557a3e3ae1f799bda8bd0afa4cfd7d97118e05229d2556
Reporting entity
- Name
- Spiraledge, Inc.norm: spiraledge
Victim entity
- Name
- Spiraledge, Inc.norm: spiraledge
Incident
- Discovered
- Oct 31, 2016
- Materiality determined
- —
- Notification sent
- Jan 12, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(73 days from discovery to filing)
- Compliance flags
- CA 60-day late · 73d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 31, 2016→ Notified: Jan 12, 201773d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.