FabFitFun
bd_50163f839ce68266 · schema v1 · pii pii-v1
Full breach record for FabFitFun →2 incidents on fileFabFitFun, Inc. disclosed a data breach involving unauthorized access to its website's member sign-up pages. Malicious code was inserted between April 26, 2020, and August 3, 2020, potentially capturing customer emails, passwords, and payment card details (including CVV) for users signing up via credit/debit cards. PayPal/Apple Pay users had emails and passwords exposed. FabFitFun engaged forensic experts, removed the code, reset passwords, and offered one year of complimentary identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 26, 2020
Begins
Sep 15, 2020
Filed
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Indiana State AGbd_7b6fb6be7b6a6ee92020-09-15Verified
- California State AGbd_1958392dde8827502020-09-18 · +3dVerified
- Oregon State AGbd_3846524d2498eaed2020-09-18 · +3dCandidate
- Washington State AGbd_856ea1b4b51736ac2020-09-18 · +3dVerified
Show 4 more filings ↓Show fewer ↑up to 13d gap
- Massachusetts State AGbd_dd1105fd2ff0fc422020-09-18 · +3dVerified
- Maine State AGbd_ff5db961d83e67fb2020-09-18 · +3dVerified
- Montana State AGbd_9ad0328ed2f0b6d02020-09-22 · +7dVerified
- New Hampshire State AGbd_707bf73e18f017fb2020-09-28 · +13dVerified
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Sep 15 (IN), last Sep 28 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.