FabFitFun
bd_707bf73e18f017fb · schema v1 · pii pii-v1
Full breach record for FabFitFun →2 incidents on fileFabFitFun, Inc. notified New Hampshire AG of a security incident where unauthorized third parties inserted malicious code on its website sign-up pages between April 26 and August 3, 2020. The code captured emails, passwords, and payment card details for customers signing up via PayPal, Apple Pay, or credit/debit cards. Approximately 505 NH residents were affected. FabFitFun removed the code, engaged forensic experts, reset passwords, and notified law enforcement.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 26, 2020
Begins
Sep 28, 2020
Filed
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Montana State AGbd_9ad0328ed2f0b6d02020-09-22 · +6dVerified
- California State AGbd_1958392dde8827502020-09-18 · +10dVerified
- Oregon State AGbd_3846524d2498eaed2020-09-18 · +10dCandidate
- Washington State AGbd_856ea1b4b51736ac2020-09-18 · +10dVerified
Show 4 more filings ↓Show fewer ↑up to 13d gap
- Massachusetts State AGbd_dd1105fd2ff0fc422020-09-18 · +10dVerified
- Maine State AGbd_ff5db961d83e67fb2020-09-18 · +10dVerified
- Delaware State AGbd_50163f839ce682662020-09-15 · +13dVerified
- Indiana State AGbd_7b6fb6be7b6a6ee92020-09-15 · +13dVerified
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Sep 15 (DE), last Sep 28 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.