TEMPUR-PEDIC MANAGEMENT, LLC
ent_019e5b56a3a1cf2020b5e86743f2284e
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
7,366
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TEMPUR-PEDIC MANAGEMENT, LLC
- Normalized
- tempur pedic management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493008MLAEZVG55IX36
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- SOMNIGROUP INTERNATIONAL INC.— per SEC Exhibit 21 filing
Disclosure history (7)newest first
- Oregon State AGas victim2017-04-12
Tempur-Pedic reported a data breach to the Oregon Attorney General. The breach was reported on 2017-04-12. The breach occurred during 2/15/2016 - 9/30/2016. The breach was discovered on 11/15/2016. Notice was sent on 4/4/2017.
- Hawaii State AGas victim2017-04-11
Tempur-Pedic, via hosting vendor Aptos, Inc., notified Hawaii consumers of a security incident where unauthorized access to the Tempurpedic.com website resulted in the capture of payment card data. The intrusion occurred between Feb and Dec 2016. 1,302 Hawaii residents were notified.
- South Carolina State AGas victim2017-04-10
Tempur-Pedic notified South Carolina residents of a security incident involving its website hosting vendor. An unauthorized individual gained access to website servers and installed malware to capture payment card information (names, addresses, card numbers, expiration dates) from transactions made on or before September 30, 2016. The vendor engaged forensic investigators, removed malware, and reported the incident to federal law enforcement. Tempur-Pedic offered one year of complimentary identity protection services.
- Montana State AGas victim2017-04-05
Tempur-Pedic notified Montana residents of a security incident involving its website hosting vendor. An unauthorized individual accessed portions of the website and installed malicious software to capture payment card information (names, addresses, card numbers, expiration dates) from purchases made prior to September 30, 2016. The vendor engaged forensic investigators, removed malware, and reported the incident to federal law enforcement. One year of complimentary identity protection services was offered to affected individuals.
- New Hampshire State AGas victim2017-04-04
Aptos submitted a supplemental notice to the New Hampshire Attorney General on April 4, 2017, regarding a breach affecting Tempur-Pedic. The notice covers 1,531 New Hampshire residents whose PII was compromised. This is a follow-up to a prior notice dated February 25, 2017.
- California State AGas victim2017-04-04
Tempur-Pedic disclosed a data breach affecting customers who made payment card purchases on Tempurpedic.com between 2016 and September 30, 2016. An unauthorized individual accessed the website servers via a third-party hosting vendor and installed malicious software to capture payment card information. Affected data includes names, addresses, email addresses, phone numbers, payment card account numbers, and expiration dates. Social Security numbers were not involved. The incident was contained, malware removed, and the company transitioned to a new hosting vendor. One year of identity protection services was offered to affected individuals.
- Washington State AGas victim2017-04-04
Tempur-Pedic notified Washington AG of a cyberattack involving malware installed on its website servers by an unauthorized party via its hosting vendor. The incident, discovered in Feb 2017, affected payment card data and PII of 7,366 Washington residents. Remediation included malware removal and enhanced security monitoring.