PAX Labs, Inc.
bd_cdfab40ab9f0cea1 · schema v1 · pii pii-v1
Full breach record for PAX Labs, Inc. →PAX Labs, Inc. notified customers of a data breach affecting approximately 6,000 individuals. Unauthorized parties gained access to cloud-based servers for PAXvapor.com and JUULvapor.com between June 25 and July 22, 2016, installing unauthorized software to steal payment card data including CVV codes. PAX detected the incident on July 15, 2016, removed the malware, engaged forensic investigators, and implemented enhanced firewall and monitoring controls. Affected individuals were offered 12 months of identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 25, 2016
Begins
Jul 15, 2016
Discovered
Aug 12, 2016
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- California State AGbd_ae35c365847dec6d2016-08-12Verified
- New Hampshire State AGbd_8bd1ff1a24c029ad2016-08-11 · +1dVerified
- Massachusetts State AGbd_a1430bc57e4c62122016-08-11 · +1dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.