HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
TEMPUR-PEDIC MANAGEMENT, LLC
bd_d46247ee45324af5 · schema v1 · pii pii-v1
Full breach record for TEMPUR-PEDIC MANAGEMENT, LLC →Tempur-Pedic experienced a data breach involving its former web hosting vendor. An unauthorized individual gained access to the website servers and installed malware to capture payment card information from transactions made between January and September 2016. Affected data included names, addresses, emails, phone numbers, and payment card details. The vendor engaged forensic investigators, removed the malware, and reported the incident to federal law enforcement. One year of complimentary identity protection services was offered to affected individuals.
California clockDiscovered Oct 1, 2016 → Notified Jan 24, 20253037d ✗ CA 60-day late26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-67320
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 4, 2017
- Raw hash
- b1f12cac1dfe2d1598cf2e807db57d0ac985f9e52407a15b2142df4844ccf6a3
Reporting entity
- Name
- Aptos, Inc. on behalf of Retailers in Attached Addendanorm: aptos inc on behalf of retailers in attached addenda
Victim entity
- Name
- TEMPUR-PEDIC MANAGEMENT, LLCnorm: tempur pedic management
Incident
- Discovered
- Oct 1, 2016
- Materiality determined
- Jan 24, 2025
- Notification sent
- Jan 24, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1056 Input CaptureT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported to federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 26 weeks(185 days from discovery to filing)
- Compliance flags
- CA 60-day late · 3037d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 1, 2016→ Notified: Jan 24, 20253037d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.