Travel Caddy, Inc. dba Travelon reported a data breach to the Montana Attorney General. The breach was reported on 2016-08-04. The breach occurred from 11/13/2015 to 6/10/2016. 3 Montana residents were affected.
Affected (this filing): 3
Clustered 2 filings across 2 jurisdictions · filed Aug 4, 2016. View entity profile → Other incidents for this victim →
incident inc_6815c14aa2564022 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
MT NH
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Nov 13, 2015
When the intrusion reportedly occurred, per the linked filings
Jul 7, 2016
Reported by NEW HAMPSHIRE AG filing
Travel Caddy, Inc. dba Travelon reported a data breach to the Montana Attorney General. The breach was reported on 2016-08-04. The breach occurred from 11/13/2015 to 6/10/2016. 3 Montana residents were affected.
Affected (this filing): 3
Travel Caddy, Inc. (dba Travelon) notified the NH Attorney General of a data breach occurring between Nov 13, 2015 and Jun 10, 2016. Malicious code on the website's server collected customer PII (names, addresses, emails) and financial data (credit card numbers, CVV2, expiration dates). The breach was discovered on July 7, 2016, when a third-party web developer alerted the company. Approximately 1,673 individuals nationwide were potentially affected, including 16 New Hampshire residents. The malicious code was deactivated, and customer notifications were sent.
Affected (this filing): 1,673
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.