Manduka
ent_019ebc9aa46845d6b9fbd9f7e88d398e
Disclosures
10
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
64,270
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Manduka
- Normalized
- manduka— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300FRO2027GFOTS73
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- New Hampshire State AGas victim2018-08-01
Manduka notified the NH AG of a malware incident on its e-commerce platform affecting payment card data (names, numbers, CVVs) for customers transacting between Feb 2017 and July 2018. The incident involved multiple malware installations and re-installations. Manduka engaged forensic investigators, notified the FBI and Secret Service, and is rebuilding its platform with MFA.
- California State AGas victim2018-06-08
Manduka experienced a data security incident involving unauthorized malware installation on its e-commerce platform. Payment card information (names, card numbers, expiration dates, security codes) for customers who used the platform between February 22, 2017, and May 20, 2018, was potentially compromised. The incident was discovered on February 25, 2018, with a second malware reinstallation detected in May 2018. Manduka engaged forensic investigators, notified law enforcement (FBI, Secret Service), and implemented remediation measures including MFA and platform migration. 9,651 California residents were notified.
- New Hampshire State AGas victim2018-03-27
Manduka notified the NH Attorney General of a data security incident discovered on Feb 25, 2018. Malware was installed on its e-commerce platform, affecting payment card info (names, numbers, expiration, CVV) of customers who purchased between Feb 22, 2017 and Mar 5, 2018. 279 NH residents were notified. Manduka engaged forensics, notified the FBI, and secured the platform.
- Washington State AGas victim2018-03-27
Manduka, a fitness equipment retailer, reported a multi-stage malware incident on its Magento e-commerce platform. Unauthorized malware installation occurred between Feb 2017 and July 2018, affecting payment card data (names, numbers, CVVs) of ~1,634 Washington residents. Manduka engaged forensic investigators, notified the FBI/Secret Service, and implemented MFA and platform migration.
- Oregon State AGas victim2018-03-27
Manduka reported a data breach to the Oregon Attorney General. The breach was reported on 2018-03-27. The breach occurred during 2/22/2017 - 3/5/2018. The breach was discovered on 2/25/2018. 64,270 individuals were affected. Notice was sent on 3/26/2018.
- California State AGas victim2018-03-27
Manduka experienced a data security incident involving unauthorized malware installation on its e-commerce web platform. The incident occurred between February 22, 2017, and March 5, 2018, and was discovered on February 25, 2018. Customer payment card information, including names, card numbers, expiration dates, and security codes, may have been compromised. Manduka notified the FBI and Secret Service and retained a forensics firm to investigate.
- Massachusetts State AGas victim2018-03-27
Manduka reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-03-27. 1,750 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-03-26
Manduka notified Montana AG of a data breach involving malware on its e-commerce platform affecting payment card data (names, numbers, expiration, CVV) for customers who purchased between Feb 22, 2017 and Mar 5, 2018. Manduka discovered the incident on Feb 25, 2018, engaged forensic investigators, and notified the FBI and Secret Service.
- Massachusetts State AGas victim2016-11-04
Manduka reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-11-04. 856 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2016-10-31
Manduka notified the NH AG of a security incident where unauthorized individuals installed malicious software on its e-commerce platform (manduka.com). The incident affected approximately 24,519 US-based individuals (including 118 NH residents) who made purchases between Jan 29 and Oct 8, 2016. Compromised data included names, addresses, usernames, passwords, and payment card details. Manduka engaged forensic experts and is offering 12 months of credit monitoring.