JAND Inc.
bd_51d95883578ecc22 · schema v1 · pii pii-v1
Full breach record for JAND Inc. →JAND Inc. d/b/a Warby Parker notified Washington AG of a credential stuffing incident affecting 951 state residents. Unauthorized parties used stolen credentials from other breaches to attempt logins between Sept 25 and Nov 26, 2018. No proof of actual data access was found, but accounts potentially contained names, emails, prescriptions, and partial card info. Customers were required to reset passwords.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 25, 2018
Begins
Nov 26, 2018
Discovered
Dec 20, 2018
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- California State AGbd_b170633faba40bb92018-12-21 · +1dCandidate
- New Hampshire State AGbd_117cd5271d2bb7d82018-12-24 · +4dVerified
- Massachusetts State AGbd_512491b6332a1e102018-12-26 · +6dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Dec 20 (WA), last Dec 26 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.