LÍLLÉbaby
bd_f92a306617ed7da4 · schema v1 · pii pii-v1
Full breach record for LÍLLÉbaby →LÍLLÉbaby reported a data security incident involving unauthorized malware installation on its e-commerce platform. The malware potentially compromised payment card information (names, card numbers, expiration dates, security codes) for customers who made purchases between June 2016 and July 9, 2018. The company discovered the incident in June 2018. 4,068 California residents were affected. LÍLLÉbaby engaged a forensics firm, removed the malware, reported to the FBI and payment card brands, and is rebuilding its web platform with enhanced security. Identity monitoring services were offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 1, 2016
Begins
Jun 1, 2018
Discovered
Aug 29, 2018
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_42f139649d2cf0362018-08-29Verified
- Oregon State AGbd_e6bf067828ae30522018-08-29Candidate
- New Hampshire State AGbd_ec62da6a823fbd402018-08-29Verified
- Washington State AGbd_f000fce9dfaaaa232018-08-29Verified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.