DisclosureLens
HackingRetail & ConsumerTechnologyRetailStolen CredentialsCapture Stored DataData ExfiltratedTargetedIdentity (basic)Financial accountFinancial credentialsMediumContained

Spiraledge - Swim Outlet.com & YogaOutlet.com

bd_3e16d794a3506395 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 31, 2016

Filed

Jan 12, 2017

To disclose

10 weeks

Affected

1,411state residents only

Confidence

64%
Full breach record for Spiraledge - Swim Outlet.com & YogaOutlet.com

Spiraledge (operating SwimOutlet.com and YogaOutlet.com) disclosed a cyber-attack occurring between May 2 and Nov 22, 2016. The company detected unusual activity on Oct 31, 2016, and confirmed the breach on Nov 28, 2016. Customer payment data (names, addresses, card numbers, CVVs) was compromised. Spiraledge engaged forensic investigators and the FBI, removed malicious software, and notified customers in January 2017.

Incident timeline

undetected · 182 days
discovery → filing · 10 weeks / 73 days

May 2, 2016

Begins

Oct 31, 2016

Discovered

Jan 12, 2017

Filed

vs. sector median

+3 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,411 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.