TEMPUR-PEDIC MANAGEMENT, LLC
bd_d441b936c45a4cf7 · schema v1 · pii pii-v1
Full breach record for TEMPUR-PEDIC MANAGEMENT, LLC →Tempur-Pedic notified South Carolina residents of a security incident involving its website hosting vendor. An unauthorized individual gained access to website servers and installed malware to capture payment card information (names, addresses, card numbers, expiration dates) from transactions made on or before September 30, 2016. The vendor engaged forensic investigators, removed malware, and reported the incident to federal law enforcement. Tempur-Pedic offered one year of complimentary identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 30, 2016
Begins
Apr 10, 2017
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Hawaii State AGbd_b9421369e4f1231a2017-04-11 · +1dVerified
- Oregon State AGbd_3b6e4ce3b3e36db22017-04-12 · +2dVerified by operator
- Montana State AGbd_4cf6fd903fad9cbf2017-04-05 · +5dVerified
- New Hampshire State AGbd_bfb66da280bec35f2017-04-04 · +6dVerified
Show 2 more filings ↓Show fewer ↑up to 6d gap
- California State AGbd_d46247ee45324af52017-04-04 · +6dVerified
- Washington State AGbd_d9ee40b43f54ddd22017-04-04 · +6dCandidate
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Apr 4 (NH), last Apr 12 (OR) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.