Sugarfina USA, LLC
bd_cbbc835a8a32a559 · schema v1 · pii pii-v1
Full breach record for Sugarfina USA, LLC →Sugarfina USA, LLC notified Montana regulators of a cyber-attack involving malicious code on its website that potentially exposed customer payment card information (names, billing addresses, card numbers, CVVs) and credentials. The unauthorized access window was November 1, 2019, to September 3, 2020. Sugarfina discovered the incident on January 15, 2021, secured the site, and launched an investigation.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 1, 2019
Begins
Jan 15, 2021
Discovered
May 25, 2021
Filed
vs. sector median
+11 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Maine State AGbd_5ca080b9a6988def2021-05-25Verified
- Massachusetts State AGbd_8fd4aa394c9b33e92021-05-25Verified
- California State AGbd_9ef0158eb8fcad352021-05-25Verified
- Oregon State AGbd_af6dc0ec43bde3f12021-05-25Verified
Show 4 more filings ↓Show fewer ↑up to 144d gap
- Indiana State AGbd_b2b0346c19ea77922021-05-25Verified
- Washington State AGbd_ce2b887a3ceb24d22021-05-25Verified
- New Hampshire State AGbd_2dd44e96e01783982021-06-01 · +7dVerified
- Illinois State AGbd_ea98cd3f8d09cd7d2021-01-01 · +144dCandidate
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Jun 1 (NH) — a 151-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.