FabFitFun
bd_856ea1b4b51736ac · schema v1 · pii pii-v1
Full breach record for FabFitFun →2 incidents on fileFabFitFun, Inc. notified Washington AG of a cybersecurity incident where an unauthorized third party inserted malicious code on customer sign-up pages between April 26 and August 3, 2020. The attack captured emails, passwords, and payment card details for approximately 11,094 Washington residents. FabFitFun engaged forensic experts, reset passwords, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 26, 2020
Begins
Aug 21, 2020
Discovered
Sep 18, 2020
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- California State AGbd_1958392dde8827502020-09-18Verified
- Oregon State AGbd_3846524d2498eaed2020-09-18Candidate
- Massachusetts State AGbd_dd1105fd2ff0fc422020-09-18Verified
- Maine State AGbd_ff5db961d83e67fb2020-09-18Verified
Show 4 more filings ↓Show fewer ↑up to 10d gap
- Delaware State AGbd_50163f839ce682662020-09-15 · +3dVerified
- Indiana State AGbd_7b6fb6be7b6a6ee92020-09-15 · +3dVerified
- Montana State AGbd_9ad0328ed2f0b6d02020-09-22 · +4dVerified
- New Hampshire State AGbd_707bf73e18f017fb2020-09-28 · +10dVerified
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Sep 15 (DE), last Sep 28 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.