Warner Music Group
bd_4c882e60c0727844 · schema v1 · pii pii-v1
Full breach record for Warner Music Group →3 incidents on fileWarner Music Group (WMG) disclosed a cybersecurity incident affecting its US-based e-commerce websites, hosted by an external service provider. Between April 25, 2020, and August 5, 2020, an unauthorized third party potentially acquired personal information, including names, addresses, and payment card details (card number, CVC/CVV, expiration date). Payments via PayPal were unaffected. WMG engaged forensic experts, notified credit card providers and law enforcement, and offered 12 months of free identity monitoring through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 25, 2020
Begins
Aug 5, 2020
Discovered
Sep 2, 2020
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- South Carolina State AGbd_07f2cbb6b77f4ab82020-09-02Verified
- Montana State AGbd_291443e8a85002962020-09-02Verified
- Washington State AGbd_adff23c1da81b4972020-09-02Candidate
- Indiana State AGbd_13e339efa758f9df2020-09-03 · +1dVerified
Show 2 more filings ↓Show fewer ↑up to 7d gap
- New Hampshire State AGbd_35175c3bfdf953a22020-09-04 · +2dVerified
- Massachusetts State AGbd_1d2a6092d2d3c24c2020-09-09 · +7dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Sep 2 (SC), last Sep 9 (MA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.