Clustered 6 filings across 6 jurisdictions · filing window Sep 15, 2020 → Sep 22, 2020. View entity profile → Other incidents for this victim →
incident inc_7d9e0a5317aa4e4c · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA DE ME MT OR WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Apr 26, 2020 → Aug 3, 2020
When the intrusion reportedly occurred, per the linked filings
May 14, 2020
Reported by CALIFORNIA AG filing
Aug 7, 2020
Reported by OREGON AG, MAINE AG filings
Aug 21, 2020
Reported by WASHINGTON AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
FabFitFun, Inc. disclosed a data breach involving unauthorized access to its website's member sign-up pages. Malicious code was inserted between April 26, 2020, and August 3, 2020, potentially capturing customer emails, passwords, and payment card details (including CVV) for users signing up via credit/debit cards. PayPal/Apple Pay users had emails and passwords exposed. FabFitFun engaged forensic experts, removed the code, reset passwords, and offered one year of complimentary identity protection services.
FabFitFun, Inc. disclosed a data breach affecting customers who signed up between April 26, 2020, and August 3, 2020. An unauthorized third party inserted malicious code on the website's new member sign-up pages, potentially capturing emails, passwords, and payment card details (including CVV and expiration dates) for credit/debit card users. The company engaged forensic experts, removed the malicious code, reset passwords, and offered one year of complimentary identity protection services.
FabFitFun, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-09-18. The breach occurred during 4/26/2020 - 5/14/2020, 5/22/2020 - 8/3/2020. The breach was discovered on 8/7/2020. 209,984 individuals were affected. Notice was sent on 9/15/2020.
Affected (this filing): 209,984
FabFitFun, Inc., a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2020-08-21 and filed notice on 2020-09-18. 11,094 Washington residents were affected. 28 days elapsed between awareness and notification. 117 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 11,094
FabFitFun, Inc. experienced an external system breach impacting approximately 209,984 individuals. The breach occurred in two periods, from April 26 to May 14, 2020, and from May 22 to August 3, 2020, with discovery on August 7, 2020. The compromised information included names and financial account or credit/debit card numbers along with their associated security codes or PINs. The company provided written notification to affected individuals and offered 12 months of identity protection services through Experian.
Affected (this filing): 209,984
FabFitFun reported a data breach to the Montana Attorney General. The breach was reported on 2020-09-22. The breach occurred from 4/26/2020 to 8/3/2020. 281 Montana residents were affected.
Affected (this filing): 281