DisclosureLens
HackingTechnologyInformationStolen CredentialsCustomer Data InvolvedCredentialsIdentity (basic)LowActive

MyFitnessPal, Inc.

bd_b68489de0920def6 · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 25, 2018

Filed

Mar 29, 2018

To disclose

4 days

Affected

Not disclosed

Confidence

64%
Full breach record for MyFitnessPal, Inc.

MyFitnessPal (owned by Under Armour) disclosed that an unauthorized party acquired user account data, including usernames, email addresses, and hashed passwords, during February 2018. The company became aware of the incident on March 25, 2018. No government-issued identifiers or payment card data were involved. The investigation is ongoing, and users are required to change their passwords.

California clockDiscovered Mar 25, 2018Notified Mar 29, 20184d CA 60-day OK4 days discovery → filing

Incident timeline

undetected · 52 days
discovery → filing · 4 days

Feb 1, 2018

Begins

Mar 25, 2018

Discovered

Mar 29, 2018

Filed

vs. sector median

18 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.