FabFitFun
ent_9bfd3426212055cd9083d486
Disclosures
12
State AG · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
209,984
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- FabFitFun
- Normalized
- fabfitfun— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- fabfitfun.com
Disclosure history (12)newest first
- New Hampshire State AGas victim2020-09-28
FabFitFun, Inc. notified New Hampshire AG of a security incident where unauthorized third parties inserted malicious code on its website sign-up pages between April 26 and August 3, 2020. The code captured emails, passwords, and payment card details for customers signing up via PayPal, Apple Pay, or credit/debit cards. Approximately 505 NH residents were affected. FabFitFun removed the code, engaged forensic experts, reset passwords, and notified law enforcement.
- Montana State AGas victim2020-09-22
FabFitFun notified Montana residents of a data breach involving unauthorized access to website sign-up pages between April 26 and August 3, 2020. Malicious code captured emails, passwords, and payment card details for PayPal/Apple Pay and credit/debit card users. FabFitFun engaged forensic experts, reset passwords, and offered one year of identity protection services.
- California State AGas victim2020-09-18
FabFitFun, Inc. disclosed a data breach affecting customers who signed up between April 26, 2020, and August 3, 2020. An unauthorized third party inserted malicious code on the website's new member sign-up pages, potentially capturing emails, passwords, and payment card details (including CVV and expiration dates) for credit/debit card users. The company engaged forensic experts, removed the malicious code, reset passwords, and offered one year of complimentary identity protection services.
- Oregon State AGas victim2020-09-18
FabFitFun, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-09-18. The breach occurred during 4/26/2020 - 5/14/2020, 5/22/2020 - 8/3/2020. The breach was discovered on 8/7/2020. 209,984 individuals were affected. Notice was sent on 9/15/2020.
- Washington State AGas victim2020-09-18
FabFitFun, Inc. notified Washington AG of a cybersecurity incident where an unauthorized third party inserted malicious code on customer sign-up pages between April 26 and August 3, 2020. The attack captured emails, passwords, and payment card details for approximately 11,094 Washington residents. FabFitFun engaged forensic experts, reset passwords, and offered credit monitoring.
- Massachusetts State AGas victim2020-09-18
FabFitFun, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-09-18. 2,184 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2020-09-18
FabFitFun, Inc. experienced an external system breach impacting approximately 209,984 individuals. The breach occurred in two periods, from April 26 to May 14, 2020, and from May 22 to August 3, 2020, with discovery on August 7, 2020. The compromised information included names and financial account or credit/debit card numbers along with their associated security codes or PINs. The company provided written notification to affected individuals and offered 12 months of identity protection services through Experian.
- Delaware State AGas victim2020-09-15
FabFitFun, Inc. disclosed a data breach involving unauthorized access to its website's member sign-up pages. Malicious code was inserted between April 26, 2020, and August 3, 2020, potentially capturing customer emails, passwords, and payment card details (including CVV) for users signing up via credit/debit cards. PayPal/Apple Pay users had emails and passwords exposed. FabFitFun engaged forensic experts, removed the code, reset passwords, and offered one year of complimentary identity protection services.
- Indiana State AGas victim2020-09-15
FabFitFun, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-04-26 and was reported on 2020-09-15. 2,065 Indiana residents were affected. 209,984 individuals affected in total.
- Massachusetts State AGas victim2020-06-02
FabFitFun, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-06-02. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2020-06-02
FabFitFun, Inc. notified New Hampshire AG of a breach where malicious code was placed on its shop website between May 2-6, 2020, using an employee's admin credentials. Discovered May 6, 2020. Impacted 4 NH residents' PII and payment data. Notification sent May 25, 2020.
- Indiana State AGas victim2020-05-25
FabFitFun, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-05-02 and was reported on 2020-05-25. 17 Indiana residents were affected. 664 individuals affected in total.