FabFitFun
bd_9ad0328ed2f0b6d0 · schema v1 · pii pii-v1
Full breach record for FabFitFun →2 incidents on fileFabFitFun notified Montana residents of a data breach involving unauthorized access to website sign-up pages between April 26 and August 3, 2020. Malicious code captured emails, passwords, and payment card details for PayPal/Apple Pay and credit/debit card users. FabFitFun engaged forensic experts, reset passwords, and offered one year of identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 26, 2020
Begins
Aug 3, 2020
Discovered
Sep 22, 2020
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- California State AGbd_1958392dde8827502020-09-18 · +4dVerified
- Oregon State AGbd_3846524d2498eaed2020-09-18 · +4dCandidate
- Washington State AGbd_856ea1b4b51736ac2020-09-18 · +4dVerified
- Massachusetts State AGbd_dd1105fd2ff0fc422020-09-18 · +4dVerified
Show 4 more filings ↓Show fewer ↑up to 7d gap
- Maine State AGbd_ff5db961d83e67fb2020-09-18 · +4dVerified
- New Hampshire State AGbd_707bf73e18f017fb2020-09-28 · +6dVerified
- Delaware State AGbd_50163f839ce682662020-09-15 · +7dVerified
- Indiana State AGbd_7b6fb6be7b6a6ee92020-09-15 · +7dVerified
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Sep 15 (DE), last Sep 28 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.