FabFitFun, Inc.

FabFitFun, Inc.

The Washington State Office of the Attorney General reported a cyberattack involving FabFitFun, Inc. on September 18, 2020. The breach occurred between April 26, 2020 and August 3, 2020, potentially affecting approximately 11,094 Washington residents. The incident involved the insertion of malicious code on the company's website, compromising names, email addresses, passwords, financial and banking information.

Source: https://www.atg.wa.gov/data-breach-notifications | https://data.wa.gov/resource/sb4j-ca4h.json?id=10313

TPRM report: https://www.rankiteo.com/company/fabfitfun

"id": "fab602072525",
"linkid": "fabfitfun",
"type": "Breach",
"date": "4/2020",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 11094,
                        'industry': 'Retail',
                        'location': 'Washington',
                        'name': 'FabFitFun, Inc.',
                        'type': 'Company'}],
 'attack_vector': 'Malicious Code Injection',
 'data_breach': {'number_of_records_exposed': 11094,
                 'personally_identifiable_information': ['names',
                                                         'email addresses'],
                 'type_of_data_compromised': ['names',
                                              'email addresses',
                                              'passwords',
                                              'financial and banking '
                                              'information']},
 'date_detected': '2020-08-03',
 'date_publicly_disclosed': '2020-09-18',
 'description': 'The Washington State Office of the Attorney General reported '
                'a cyberattack involving FabFitFun, Inc. on September 18, '
                '2020. The breach occurred between April 26, 2020 and August '
                '3, 2020, potentially affecting approximately 11,094 '
                'Washington residents. The incident involved the insertion of '
                "malicious code on the company's website, compromising names, "
                'email addresses, passwords, financial and banking '
                'information.',
 'impact': {'data_compromised': ['names',
                                 'email addresses',
                                 'passwords',
                                 'financial and banking information']},
 'references': [{'date_accessed': '2020-09-18',
                 'source': 'Washington State Office of the Attorney General'}],
 'title': 'FabFitFun Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.