Manduka
bd_459f89eec1979764 · schema v1 · pii pii-v1
Full breach record for Manduka →3 incidents on fileManduka, a fitness equipment retailer, reported a multi-stage malware incident on its Magento e-commerce platform. Unauthorized malware installation occurred between Feb 2017 and July 2018, affecting payment card data (names, numbers, CVVs) of ~1,634 Washington residents. Manduka engaged forensic investigators, notified the FBI/Secret Service, and implemented MFA and platform migration.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 22, 2017
Begins
Feb 25, 2018
Discovered
Mar 27, 2018
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_3e061c3e758c0dce2018-03-27Verified
- Oregon State AGbd_5ecb4e4d561a06bf2018-03-27Verified
- California State AGbd_7ff02f57c56732092018-03-27Verified
- Montana State AGbd_900e824b2ddbde8d2018-03-26 · +1dCandidate
Show 2 more filings ↓Show fewer ↑up to 127d gap
- California State AGbd_197f9054f6cba4652018-06-08 · +73dVerified
- New Hampshire State AGbd_7e59e035c09ab18b2018-08-01 · +127dVerified
Filing propagation · 7 filings · 5 states
View merged incident ↗Pattern: first filing Mar 26 (MT), last Aug 1 (NH) — a 128-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.