HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowResolved
FabFitFun
bd_50163f839ce68266 · schema v1 · pii pii-v1
Full breach record for FabFitFun →FabFitFun, Inc. disclosed a data breach involving unauthorized access to its website's member sign-up pages. Malicious code was inserted between April 26, 2020, and August 3, 2020, potentially capturing customer emails, passwords, and payment card details (including CVV) for users signing up via credit/debit cards. PayPal/Apple Pay users had emails and passwords exposed. FabFitFun engaged forensic experts, removed the code, reset passwords, and offered one year of complimentary identity protection services.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1958392dde882750California State AGfiled 2020-09-18(3d gap)Verified
- bd_3846524d2498eaedOregon State AGfiled 2020-09-18(3d gap)Candidate
- bd_856ea1b4b51736acWashington State AGfiled 2020-09-18(3d gap)Verified
- bd_ff5db961d83e67fbMaine State AGfiled 2020-09-18(3d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_9ad0328ed2f0b6d0Montana State AGfiled 2020-09-22(7d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/10/FabFitFunSample-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2020
- Raw hash
- 60b78d1549a7f1c41dc5614f2c88f06f2f40e287b3f3847f701d8097beef5753
Reporting entity
- Name
- FabFitFunnorm: fabfitfun
Victim entity
- Name
- FabFitFunnorm: fabfitfun
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the matter to law enforcement and are cooperating with the investigation
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.