JAND Inc.
bd_b170633faba40bb9 · schema v1 · pii pii-v1
Full breach record for JAND Inc. →Warby Parker (JAND Inc.) notified the California AG of a credential stuffing incident where attackers used usernames and passwords obtained from other breaches to attempt unauthorized logins to customer accounts between Sept 25 and Nov 30, 2018. The company detected unusual activity on Nov 26, 2018. Approximately 30,170 California customers were affected. Data potentially accessed included names, emails, prescription info, and last four digits of payment cards. Warby Parker required password resets and reported the incident to the FBI.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 25, 2018
Begins
Nov 26, 2018
Discovered
Dec 21, 2018
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Washington State AGbd_51d95883578ecc222018-12-20 · +1dVerified
- New Hampshire State AGbd_117cd5271d2bb7d82018-12-24 · +3dVerified
- Massachusetts State AGbd_512491b6332a1e102018-12-26 · +5dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Dec 20 (WA), last Dec 26 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.