Travel Caddy, Inc.
bd_883eb11ac3b53500 · schema v1 · pii pii-v1
Full breach record for Travel Caddy, Inc. →Travel Caddy, Inc. (dba Travelon) notified the NH Attorney General of a data breach occurring between Nov 13, 2015 and Jun 10, 2016. Malicious code on the website's server collected customer PII (names, addresses, emails) and financial data (credit card numbers, CVV2, expiration dates). The breach was discovered on July 7, 2016, when a third-party web developer alerted the company. Approximately 1,673 individuals nationwide were potentially affected, including 16 New Hampshire residents. The malicious code was deactivated, and customer notifications were sent.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 13, 2015
Begins
Jul 7, 2016
Discovered
Aug 4, 2016
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_28dec55f16d5ac4f2016-08-04Candidate
- Massachusetts State AGbd_f6a25a25ae547f942016-08-09 · +5dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Aug 4 (MT), last Aug 9 (MA) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.