Sapphire Foxx
bd_bc38e8180c8ba969 · schema v1 · pii pii-v1
Sapphire Foxx Beyond experienced a data breach involving malware installed on its website between June and December 2020. The malware compromised user credentials (usernames and passwords) and, for some users, credit card information entered on the site. The company retained forensic experts, removed the malware, mandated password resets, and offered identity protection services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 1, 2020
Begins
Aug 1, 2020
Discovered
Jan 26, 2021
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_2777ab4b8c876f292021-01-26Verified
- Massachusetts State AGbd_f286b2725d82d6e52021-01-26Verified
- Idaho State AGbd_cab4e57fe15bb4f72021-01-27 · +1dVerified
- New Hampshire State AGbd_a747be8af28a70b42021-01-28 · +2dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.