Julep Beauty
bd_e44398de84097367 · schema v1 · pii pii-v1
Full breach record for Julep Beauty →2 incidents on fileJulep Beauty, Inc. notified Montana residents that an unauthorized user injected code into its website between Oct 12-16, 2018, redirecting payment info. Compromised data included names, addresses, credit card numbers, and security codes for new card users. Julep removed the code and secured the server. Notices sent Nov 7, 2018.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 12, 2018
Begins
Nov 7, 2018
Filed
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_8b82c87aec384f7c2018-11-08 · +1dVerified
- New Hampshire State AGbd_dd3eae54268c5e132018-11-13 · +6dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Nov 7 (MT), last Nov 13 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.