DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Financial accountCredentialsLowResolved

FabFitFun

bd_50163f839ce68266 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Sep 15, 2020

To disclose

Affected

Not disclosed

Linked

9 filings

Confidence

66%
Full breach record for FabFitFun2 incidents on file

FabFitFun, Inc. disclosed a data breach involving unauthorized access to its website's member sign-up pages. Malicious code was inserted between April 26, 2020, and August 3, 2020, potentially capturing customer emails, passwords, and payment card details (including CVV) for users signing up via credit/debit cards. PayPal/Apple Pay users had emails and passwords exposed. FabFitFun engaged forensic experts, removed the code, reset passwords, and offered one year of complimentary identity protection services.

Incident timeline

Apr 26, 2020

Begins

Sep 15, 2020

Filed

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 13d gap

Filing propagation · 9 filings · 9 states

View merged incident ↗

Pattern: first filing Sep 15 (IN), last Sep 28 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.