CAPSULE GROUP, LLC
bd_7fdbc72be00aa912 · schema v1 · pii pii-v1
Full breach record for CAPSULE GROUP, LLC →On April 5, 2022, Capsule discovered that unauthorized threat actors gained access to certain customer accounts. The incident involved demographic information (name, email, phone, address, DOB, sex), health information (medical conditions, prescribed medications), past order history, limited payment information (last 4 digits of card, expiration date), insurance information, and chat messages. Capsule engaged a third-party forensic firm, reset passwords, implemented additional security safeguards, and offered 12 months of complimentary Experian IdentityWorks identity protection services.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555781
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 30, 2022
- Raw hash
- 639dd78a8b0c28e278990c5be4798d9bce9ba37fd9c7920a783b0b77c8196e34
Reporting entity
- Name
- CAPSULE GROUP, LLCnorm: capsule group
- Domain
- capsule.com
Victim entity
- Name
- CAPSULE GROUP, LLCnorm: capsule group
- Domain
- capsule.com
Incident
- Discovered
- Apr 5, 2022
- Materiality determined
- —
- Notification sent
- May 27, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 52d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 5, 2022→ Notified: May 27, 202252d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.