DisclosureLens
HackingOtherStolen CredentialsCustomer Data InvolvedIdentity (basic)MediumContained

AARP.org

bd_4becd0d0a4cea3ad · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 6, 2020

Filed

Jul 6, 2020

To disclose

4 weeks

Affected

1,456state residents only

Confidence

69%
Full breach record for AARP.org

AARP reported unauthorized access attempts on AARP.org on June 6, 2020, using credentials stolen from a third-party breach. Approximately 1,456 Washington residents were affected. The incident involved user profile data (date of birth). AARP required password resets and notified users via email on June 8 and mail on July 6, 2020.

Washington clock WA AG ≤30d4 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 4 weeks / 30 days

Jun 6, 2020

Begins

Jun 6, 2020

Discovered

Jul 6, 2020

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,456 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.