DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitDelayed DiscoveryFinancial accountIdentity (basic)PCILowContained

Nuna Baby Essentials, Inc.

bd_bb40bd92db0b3ff5 · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 22, 2021

Filed

Jan 21, 2022

To disclose

4 weeks

Affected

816state residents only

Linked

8 filings

Confidence

69%
Full breach record for Nuna Baby Essentials, Inc.3 incidents on file

Nuna Baby Essentials, Inc. disclosed a cybersecurity incident where malicious code was present on its website from March 26, 2020, to April 7, 2021. Discovered on December 22, 2021, the incident compromised payment card information (number, expiration, CVV, billing/shipping addresses) for approximately 816 Washington residents. Nuna reported the incident to law enforcement and offered one year of Experian identity protection services.

Incident timeline

undetected · 636 days
discovery → filing · 4 weeks / 30 days

Mar 26, 2020

Begins

Dec 22, 2021

Discovered

Jan 21, 2022

Filed

vs. sector median

3 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filings

Filing propagation · 8 filings · 8 states

View merged incident ↗
Oregon State AGJan 21 · first
Montana State AGJan 21 · first
Massachusetts State AGJan 21 · first
Indiana State AGJan 21 · first
New Hampshire State AGJan 21 · first
Maine State AGJan 21 · first
California State AGJan 21 · first
Washington State AGJan 21 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.