Manduka
bd_7e59e035c09ab18b · schema v1 · pii pii-v1
Full breach record for Manduka →3 incidents on fileManduka notified the NH AG of a malware incident on its e-commerce platform affecting payment card data (names, numbers, CVVs) for customers transacting between Feb 2017 and July 2018. The incident involved multiple malware installations and re-installations. Manduka engaged forensic investigators, notified the FBI and Secret Service, and is rebuilding its platform with MFA.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 22, 2017
Begins
Feb 25, 2018
Discovered
Aug 1, 2018
Filed
vs. sector median
+15 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- California State AGbd_197f9054f6cba4652018-06-08 · +54dVerified
- New Hampshire State AGbd_3e061c3e758c0dce2018-03-27 · +127dVerified
- Washington State AGbd_459f89eec19797642018-03-27 · +127dVerified
- Oregon State AGbd_5ecb4e4d561a06bf2018-03-27 · +127dVerified
Show 2 more filings ↓Show fewer ↑up to 128d gap
- California State AGbd_7ff02f57c56732092018-03-27 · +127dVerified
- Montana State AGbd_900e824b2ddbde8d2018-03-26 · +128dCandidate
Filing propagation · 7 filings · 5 states
View merged incident ↗Pattern: first filing Mar 26 (MT), last Aug 1 (NH) — a 128-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.