PAX Labs, Inc.
bd_ae35c365847dec6d · schema v1 · pii pii-v1
Full breach record for PAX Labs, Inc. →PAX Labs, Inc. disclosed a data breach affecting approximately 6,000 customers of its e-commerce sites PAXvapor.com and JUULvapor.com. Unauthorized parties accessed a cloud-based server between June 25 and July 22, 2016, installing malware to capture payment card data including cardholder names, addresses, card numbers, expiration dates, and CVV codes. The incident was discovered on July 15, 2016. PAX removed the malware, engaged forensic investigators, and implemented enhanced firewall rules and monitoring. Affected individuals were offered 12 months of identity protection.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 25, 2016
Begins
Jul 15, 2016
Discovered
Aug 12, 2016
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_cdfab40ab9f0cea12016-08-12Candidate
- New Hampshire State AGbd_8bd1ff1a24c029ad2016-08-11 · +1dVerified
- Massachusetts State AGbd_a1430bc57e4c62122016-08-11 · +1dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.