Princess Polly Group Pty. Ltd.
bd_c7693b5f3079e6a2 · schema v1 · pii pii-v1
Full breach record for Princess Polly Group Pty. Ltd. →Princess Polly Group Pty Ltd notified the California AG of unauthorized access to its Australian website between Nov 1, 2018, and Apr 29, 2019. An unidentified third party accessed personal information (name, address, email, phone, DOB, username, password) and payment details for some customers. The US website was not affected. The company engaged external IT and cyber security consultants to investigate and confirmed the site is secure. They upgraded their payment processor to Braintree. No Afterpay/PayPal payment info was affected.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 1, 2018
Begins
Apr 29, 2019
Discovered
Jun 7, 2019
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Washington State AGbd_243e455eea2d8d5d2019-06-07Verified
- Massachusetts State AGbd_5ee66b78eece5a852019-06-07Verified
- Montana State AGbd_b0a23f6591c1325f2019-06-06 · +1dVerified by operator
- New Hampshire State AGbd_7d21581291709ebe2019-06-03 · +4dVerified
Show 1 more filing ↓Show fewer ↑up to 8d gap
- Oregon State AGbd_1ff09f03b52d883e2019-05-30 · +8dCandidate
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing May 30 (OR), last Jun 7 (CA) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.