Sugarfina USA, LLC
bd_9ef0158eb8fcad35 · schema v1 · pii pii-v1
Full breach record for Sugarfina USA, LLC →Sugarfina USA, LLC reported a cyber-attack involving malicious code on its website that may have allowed unauthorized access to customer payment card information (cardholder name, billing address, credit card number, expiration date, CVV, and potentially username/password) for orders placed between November 1, 2019, and September 3, 2020. The incident was discovered on January 15, 2021. Sugarfina secured its website and is notifying affected individuals and regulators.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 1, 2019
Begins
Jan 15, 2021
Discovered
May 25, 2021
Filed
vs. sector median
+11 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Maine State AGbd_5ca080b9a6988def2021-05-25Verified
- Massachusetts State AGbd_8fd4aa394c9b33e92021-05-25Verified
- Oregon State AGbd_af6dc0ec43bde3f12021-05-25Verified
- Indiana State AGbd_b2b0346c19ea77922021-05-25Verified
Show 4 more filings ↓Show fewer ↑up to 144d gap
- Montana State AGbd_cbbc835a8a32a5592021-05-25Verified
- Washington State AGbd_ce2b887a3ceb24d22021-05-25Verified
- New Hampshire State AGbd_2dd44e96e01783982021-06-01 · +7dVerified
- Illinois State AGbd_ea98cd3f8d09cd7d2021-01-01 · +144dCandidate
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Jun 1 (NH) — a 151-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.