Clustered 5 filings across 4 jurisdictions · filing window Mar 26, 2018 → Jun 8, 2018. View entity profile → Other incidents for this victim →
incident inc_489bd6cb9c894e89 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA MT OR WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Feb 22, 2017
When the intrusion reportedly occurred, per the linked filings
Feb 25, 2018
Reported by WASHINGTON AG, OREGON AG, CALIFORNIA AG filings
Manduka reported a data security incident involving unauthorized malware installation on its e-commerce platform. The incident affected payment card information (names, card numbers, expiration dates, security codes) of customers who used the platform between February 22, 2017, and May 20, 2018. Manduka notified 9,616 California residents, engaged forensic investigators, and reported the incident to the FBI and Secret Service. Remediation included removing malware, implementing MFA, and rebuilding the e-commerce site.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Manduka reported a data breach to the Montana Attorney General. The breach was reported on 2018-03-26. The breach occurred from 2/22/2017 to 3/5/2018. 169 Montana residents were affected.
Affected (this filing): 169
Manduka, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2018-02-25 and filed notice on 2018-03-27. 1,634 Washington residents were affected. 30 days elapsed between awareness and notification. 0 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 1,634
Manduka reported a data breach to the Oregon Attorney General. The breach was reported on 2018-03-27. The breach occurred during 2/22/2017 - 3/5/2018. The breach was discovered on 2/25/2018. 64,270 individuals were affected. Notice was sent on 3/26/2018.
Affected (this filing): 64,270
Manduka notified California AG of a data breach involving unauthorized malware installation on its e-commerce platform. The incident occurred between Feb 22, 2017, and Mar 5, 2018, potentially compromising payment card info (names, card numbers, expiration dates, security codes) of customers. Manduka engaged forensic investigators, reported to the FBI and Secret Service, and notified payment card brands.
Affected (this filing): 9,651