DisclosureLens
MalwareTechnologyInformationRansomwareData EncryptedTargetedCredentialsFinancial accountLowContained

Sapphire Foxx

bd_bc38e8180c8ba969 · schema v1 · pii pii-v1

Severity

Low

Discovered

Aug 1, 2020

Filed

Jan 26, 2021

To disclose

25 weeks

Affected

5state residents only

Linked

5 filings

Confidence

65%

Sapphire Foxx Beyond experienced a data breach involving malware installed on its website between June and December 2020. The malware compromised user credentials (usernames and passwords) and, for some users, credit card information entered on the site. The company retained forensic experts, removed the malware, mandated password resets, and offered identity protection services to affected individuals.

Incident timeline

undetected · 61 days
discovery → filing · 25 weeks / 178 days

Jun 1, 2020

Begins

Aug 1, 2020

Discovered

Jan 26, 2021

Filed

vs. sector median

+7 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Indiana State AGJan 26 · first
Massachusetts State AGJan 26 · first
Montana State AGJan 26 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.