KandyPens, Inc.
bd_fc3c743049d16574 · schema v1 · pii pii-v1
Full breach record for KandyPens, Inc. →2 incidents on fileKandyPens, Inc. notified the NH Attorney General of a data security incident discovered in January 2020. Unauthorized access to the online payment platform compromised customer names and credit/debit card details (including CVVs) entered between March 7, 2019, and February 13, 2020. 292 NH residents were notified on April 20, 2020. KandyPens engaged forensic investigators, remediated the vulnerability, and increased monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 7, 2019
Begins
Jan 1, 2020
Discovered
Apr 21, 2020
Filed
vs. sector median
+8 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- California State AGbd_25e5d4335dc9bc382020-04-20 · +1dVerified
- Indiana State AGbd_59330e0f544dec582020-04-20 · +1dVerified
- Oregon State AGbd_979fa051fb8fb42e2020-04-20 · +1dCandidate
- Montana State AGbd_bf8f69e6defa73e22020-04-20 · +1dVerified by operator
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.