FabFitFun
ent_37bd4b0d371c00a7d58e30f6
Disclosures
6
State AG · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
209,984
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- FabFitFun
- Normalized
- fabfitfun— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- 🦬Montana State AGas victim2020-09-22
FabFitFun reported a data breach to the Montana Attorney General. The breach was reported on 2020-09-22. The breach occurred from 4/26/2020 to 8/3/2020. 281 Montana residents were affected.
- 🐻California State AGas victim2020-09-18
FabFitFun, Inc. disclosed a data breach affecting customers who signed up between April 26, 2020, and August 3, 2020. An unauthorized third party inserted malicious code on the website's new member sign-up pages, potentially capturing emails, passwords, and payment card details (including CVV and expiration dates) for credit/debit card users. The company engaged forensic experts, removed the malicious code, reset passwords, and offered one year of complimentary identity protection services.
- 🦫Oregon State AGas victim2020-09-18
FabFitFun, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-09-18. The breach occurred during 4/26/2020 - 5/14/2020, 5/22/2020 - 8/3/2020. The breach was discovered on 8/7/2020. 209,984 individuals were affected. Notice was sent on 9/15/2020.
- 🌲Washington State AGas victim2020-09-18
FabFitFun, Inc., a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2020-08-21 and filed notice on 2020-09-18. 11,094 Washington residents were affected. 28 days elapsed between awareness and notification. 117 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2020-09-18
FabFitFun, Inc. experienced an external system breach impacting approximately 209,984 individuals. The breach occurred in two periods, from April 26 to May 14, 2020, and from May 22 to August 3, 2020, with discovery on August 7, 2020. The compromised information included names and financial account or credit/debit card numbers along with their associated security codes or PINs. The company provided written notification to affected individuals and offered 12 months of identity protection services through Experian.
- 💎Delaware State AGas victim2020-09-15
FabFitFun, Inc. disclosed a data breach involving unauthorized access to its website's member sign-up pages. Malicious code was inserted between April 26, 2020, and August 3, 2020, potentially capturing customer emails, passwords, and payment card details (including CVV) for users signing up via credit/debit cards. PayPal/Apple Pay users had emails and passwords exposed. FabFitFun engaged forensic experts, removed the code, reset passwords, and offered one year of complimentary identity protection services.