TEMPUR-PEDIC MANAGEMENT, LLC
bd_d46247ee45324af5 · schema v1 · pii pii-v1
Full breach record for TEMPUR-PEDIC MANAGEMENT, LLC →Tempur-Pedic disclosed a data breach affecting customers who made payment card purchases on Tempurpedic.com between 2016 and September 30, 2016. An unauthorized individual accessed the website servers via a third-party hosting vendor and installed malicious software to capture payment card information. Affected data includes names, addresses, email addresses, phone numbers, payment card account numbers, and expiration dates. Social Security numbers were not involved. The incident was contained, malware removed, and the company transitioned to a new hosting vendor. One year of identity protection services was offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2016
Begins
Apr 4, 2017
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_bfb66da280bec35f2017-04-04Verified
- Washington State AGbd_d9ee40b43f54ddd22017-04-04Candidate
- Montana State AGbd_4cf6fd903fad9cbf2017-04-05 · +1dVerified
- South Carolina State AGbd_d441b936c45a4cf72017-04-10 · +6dVerified
Show 2 more filings ↓Show fewer ↑up to 8d gap
- Hawaii State AGbd_b9421369e4f1231a2017-04-11 · +7dVerified
- Oregon State AGbd_3b6e4ce3b3e36db22017-04-12 · +8dVerified by operator
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Apr 4 (NH), last Apr 12 (OR) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.