DisclosureLens
MalwareRetail & ConsumerManufacturingRetailRansomwareCapture Stored DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIdentity (basic)Financial accountMediumContained

TEMPUR-PEDIC MANAGEMENT, LLC

bd_d9ee40b43f54ddd2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 6, 2017

Filed

Apr 4, 2017

To disclose

8 weeks

Affected

7,366state residents only

Linked

7 filings

Confidence

70%
Full breach record for TEMPUR-PEDIC MANAGEMENT, LLC

Tempur-Pedic notified Washington AG of a cyberattack involving malware installed on its website servers by an unauthorized party via its hosting vendor. The incident, discovered in Feb 2017, affected payment card data and PII of 7,366 Washington residents. Remediation included malware removal and enhanced security monitoring.

Incident timeline

undetected · 346 days
discovery → filing · 8 weeks / 57 days

Feb 26, 2016

Begins

Feb 6, 2017

Discovered

Apr 4, 2017

Filed

vs. sector median

+1 wks slower

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 8d gap

Filing propagation · 7 filings · 7 states

View merged incident ↗
California State AGApr 4 · first
Washington State AGApr 4 · first · this page

Pattern: first filing Apr 4 (NH), last Apr 12 (OR) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.