notice of data breach - attorney general of california inc multiple notices... · [customer name]...

26
[Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]: We write to inform you of an incident involving access to information associated with online purchases made on our website www.alphaindustries.com and www.shopalphaindustries.com which resolves to www.alphaindustries.com. Although we are unaware of any actual misuse of your information, we are providing notice to you and other potentially affected customers about the incident, and about tools you can use to protect yourself against possible identity theft or fraud. What Happened? We were informed on February 6, 2017 that our website www.alphaindustries.com experienced an intrusion last year. Our site is operated for us by a third-party platform provider, Aptos, and it was Aptos that experienced the intrusion. To date, the investigation indicates that the intrusion began in approximately February 2016 and ended in December 2016. The intruder(s) placed malware on Aptos’ servers, and by doing so gained access to our customers’ payment card data, including payment card numbers. The intruder(s) also had access to historical payment card data. Because you have provided your payment card information to us in the past, we are notifying you about this data breach. You may wonder why you are hearing about the breach now. Aptos did not discover the breach until November 2016. In addition, law enforcement is investigating, and asked that notification to customers be delayed to allow the investigation to move forward. What Information Was Involved?

Upload: haxuyen

Post on 06-Feb-2018

218 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

[Customer name][Customer address][City, State, Zip]

Notice of Data Breach

Dear [Customer name]:

We write to inform you of an incident involving access to information associated with onlinepurchases made on our website www.alphaindustries.com and www.shopalphaindustries.comwhich resolves to www.alphaindustries.com. Although we are unaware of any actual misuse ofyour information, we are providing notice to you and other potentially affected customers aboutthe incident, and about tools you can use to protect yourself against possible identity theft orfraud.

What Happened?

We were informed on February 6, 2017 that our website www.alphaindustries.com experiencedan intrusion last year. Our site is operated for us by a third-party platform provider, Aptos, and itwas Aptos that experienced the intrusion.

To date, the investigation indicates that the intrusion began in approximately February 2016 andended in December 2016. The intruder(s) placed malware on Aptos’ servers, and by doing sogained access to our customers’ payment card data, including payment card numbers. Theintruder(s) also had access to historical payment card data. Because you have provided yourpayment card information to us in the past, we are notifying you about this data breach.

You may wonder why you are hearing about the breach now. Aptos did not discover the breachuntil November 2016. In addition, law enforcement is investigating, and asked that notificationto customers be delayed to allow the investigation to move forward.

What Information Was Involved?

Page 2: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

The information that the intruder(s) had access to includes your first and last name, your address,your phone number, email address and any debit or credit card numbers with expiration datesyou may have used on our website. To date, no security codes, CVV codes, PIN numbers, socialsecurity numbers, passwords, or any other personal identification numbers involving ourcustomer information was accessed.

What Are We Doing?

Aptos has worked with a leading cybersecurity firm to remove the malware from its systems andis actively monitoring the platform to safeguard personal information.

Aptos has also contacted and offered its cooperation to federal law enforcement, and steps weretaken to supply the numbers of affected cards to their issuers for monitoring. Also, even thoughthis incident did not involve security codes, CVV codes, PIN numbers, social security numbers,passwords, or any other personal identification numbers, we are offering complimentary creditmonitoring and an identity theft protection product by Equifax to help alleviate any concerns youmay have.

What You Can Do.

To protect yourself from the possibility of identity theft, we recommend you immediately contactyour credit or debit card company and inform them that your card information may have beencompromised, so that they can issue you a replacement card. While we do not believe there hasbeen any actual misuse of your information, we suggest you remain vigilant and review yourbanking and card statements as well as credit reports, and report any suspicious activity to therelevant financial institution.

You should also promptly report any fraudulent activity or any suspected incidence of identitytheft to proper law enforcement authorities, your state attorney general, and/or the Federal TradeCommission. You can also contact these sources about steps you can take to avoid identity theft.

Your state attorney general can be contacted at [phone number, address, and website].

To contact the FTC and file a complaint, go to www.ftc.gov/idtheft or call 1-877-ID-THEFT(877-438-4338). Complaints filed with the FTC will be added to the FTC's Identity Theft DataClearinghouse, which is a database made available to law enforcement agencies.

You can also contact one of the three major credit bureaus to monitor your credit report for anysuspicious activity. You should immediately notify the credit bureaus if your credit reports showanything suspicious. The credit bureau can be contacted as follows:

Experian(888) 397-3742

www.experian.com/fraud

Equifax(888) 766-0008

www.alerts.equifax.com

TransUnion(800) 680-7289

https://fraud.transunion.com

Page 3: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

As a precautionary measure to help better protect your credit file from potential misuse, we havepartnered with Equifax ® to provide its Credit Watch TM Silver credit monitoring and identitytheft protection product for one year at no charge to you.

If you choose to take advantage of this Equifax Credit Watch Silver product, it will provide youwith a notification of key changes to your Equifax credit file, up to $25,000 Identity TheftInsurance Coverage, automatic fraud alerts, access to your Equifax credit report and IdentityRestoration. To enroll in Equifax Credit Watch Silver, you may sign up online atwww.myservices.equifax.com/silver. You must complete the enrollment process for EquifaxCredit Watch Silver by June 1, 2017.

Even if you decide not to take advantage of this offer, you may still receive Equifax IdentityRestoration in the event that you become victim of identity theft by calling 877-xxx-xxxx, 9:00a.m. to 8:00 p.m. EST, Monday through Friday, before March 1, 2018.

For More Information

We at Alpha Industries take the security of our customer information very seriously and trulyregret any inconvenience that this incident may have caused you.

If you have any questions about this incident or any of the products we are making available toyou, please call 844-xxx-xxx Monday through Friday from 9:00 a.m. to 9:00 p.m. EST.

We thank you for your patronage, your understanding and your patience.

Sincerely,

Colin IsraelCOO and CFO

Page 4: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

* 9Y\XO 5\S`O B_S^O (')

7YVM\YP^# @2 (0'*)

/++$*.($,**,

(' K%W% e ,1*' Z%W% 6BC NKSVc

!]OO \O`O\]O ]SNO"

H5K^OI

f7S\]^JXKWOh f<K]^JXKWOh

f2NN\O]]J(h# fB_S^O&2Z^h

f4S^ch# fB^K^Oh fGSZh

015,&( 1) '$5$ %3($&+

5OK\ f7S\]^JXKWOh f<K]^JXKWOh#

28 4I8 RI@ME> KF EFM9T TFP 45FPK 4 J86PI@KT @E6@78EK K?4K @EQFCQ8J TFPI G4TD8EK 64I7 @E9FID4MFE%

7@9J +9FF=D=<# DO _]O K ^RS\N ZK\^c ]O\`SMO Z\Y`SNO\# 2Z^Y]# ^Y WKSX^KSX Y_\ NK^KLK]O YP M_]^YWO\ Y\NO\SXQ

@E9FID4MFEY (E +FQ8D58I jhikW "GKFJ 7@J6FQ8I87 @E7@64MFEJ K?4K @KJ JTJK8DJ ?47 588E 6FDGIFD@J87 4E7

GIFDGKCT I8GFIK87 @KJ JPJG@6@FEJ KF 1Y/Y C4R 8E9FI68D8EK 4>8E6@8JW R?F I8HP8JK87 "GKFJ 78C4T 4ET EFM<64MFE

F9 K?8 @E6@78EK KF K?@I7 G4IM8JW @E6CP7@E> "KC4EM6 $@>4I $FYW 7PI@E> K?8 6I@D@E4C @EQ8JM>4MFEY ,E &85IP4IT ihW

jhilW "GKFJ EFM<87 PJ K?4K K?8I8 ?47 588E I8DFK8 4668JJ @EKIPJ@FE KF "GKFJZ JTJK8DJ K?4K I8JPCK87 @E

PE4PK?FI@U87 4668JJ KF FPI 6PJKFD8IJZ @E9FID4MFEY "K K?@J MD8W R8 4I8 PE4R4I8 F9 4ET I8GFIKJ F9 6I87@K 64I7

P\K_N Y\ Y^RO\ WS]_]O YP Y_\ M_]^YWO\]d NK^K%

/71A '<5=?;1B=< /1@ '<F9=F43J 0?8 @EKIPJ@FE I8JPCK87 @E 4668JJ KF FEC@E8 KI4EJ46MFE 74K4W @E6CP7@E> TFPI <IJK

4E7 C4JK E4D8W 5@CC@E> 4E7 J?@GG@E> 477I8JJa8JbW G?FE8 EPD58IW G4TD8EK 64I7 @E9FID4MFE @E6CP7@E> 466FPEK

EPD58I 4E7 8SG@I4MFE 74K8Y

7@9J 7= $H= 'EAD?! #5 8,97659, ;6 ;0,9, ,=,5;9A "7;69 0(9 >682,+ >1;0 ( 3,(+15/ *?),89,*<81;? .84 ;6

\OWY`O ^RO WKVaK\O P\YW KXN _ZNK^O ^RO ]OM_\S^c YP S^] ]c]^OW]# SXMV_NSXQ ]^\OXQ^ROXSXQ KMMO]] MYX^\YV]%

"77@MFE4CCTW "KC4EM6 $@>4I $FY ?4J 4II4E>87 KF ?4Q8 "CC$C84I (% GIFK86K TFPI @78EMKT 9FI ij DFEK?J 4K EF 6FJK KF

TFPY 0?8 9FCCFR@E> @78EMKT GIFK86MFE J8IQ@68J JK4IK FE K?8 74K8 F9 K?@J EFM68 4E7 TFP 64E PJ8 K?8D 4K 4ET MD8

N_\SXQ ^RO XOb^ (* WYX^R]1

"99#941? '34<BAH ,4>18?K 0?@J J8IQ@68 @J 4PKFD4M64CCT 4Q4@C45C8 KF TFP R@K? EF 8EIFCCD8EK I8HP@I87Y (9 4

GIF5C8D 4I@J8JW J@DGCT 64CC ]%(%`-?FE8^ 4E7 4 787@64K87 @EQ8JM>4KFI R@CC ?8CG I86FQ8I <E4E6@4C CFJJ8JW

I8JKFI8 TFPI 6I87@K 4E7 D4B8 JPI8 TFPI @78EMKT @J I8KPIE87 KF @KJ GIFG8I 6FE7@MFEY

$BB&B=9H &H=<AJ /EDAJEHAD?" 0?@J J8IQ@68 F;8IJ 477@MFE4C C4T8IJ F9 GIFK86MFE @E6CP7@E> 6I87@K DFE@KFI@E>

4E7 4 fi D@CC@FE @78EMKT K?8= @EJPI4E68 GFC@6TY 0F PJ8 K?@J J8IQ@68W TFP R@CC E887 KF GIFQ@78 TFPI G8IJFE4C

@E9FID4MFE KF "CC$C84I (%Y 3FP D4T J@>E PG FEC@E8 4K 8EIFCCY4CC6C84I@7Y6FD PJ@E> K?8 9FCCFR@E> I878DGMFE

6F78X c.878DGMFE`$F78dY

"77@MFE4C JK8GJ D4T 58 I8HP@I87 5T TFP @E FI78I KF 46MQ4K8 TFPI G?FE8 4C8IKJ 4E7 DFE@KFI@E> FGMFEJY

+A74? ';>=?A1<A '<5=?;1B=<L -C84J8 I8Q@8R K?8 [&PIK?8I /K8GJ 4E7 $FEK46K )@JK\ @E9FID4MFE FE K?8 I8Q8IJ8

J@78 F9 K?@J C8O8I R?@6? @78EM<8J 477@MFE4C JK8GJ KF K4B8 KF GIFK86K TFPI @E9FID4MFEY

%=? )=?4 '<5=?;1B=<L (9 TFP ?4Q8 9PIK?8I HP8JMFEJ FI 6FE68IEJ 45FPK K?@J @E6@78EKW GC84J8 64CC "CC$C84I (%W

=YXNKc ^R\Y_QR BK^_\NKc# / K%W% e / Z%W% 4BC%

DO ^KUO KVV Z\S`KMc KXN ]OM_\S^c SXMSNOX^] ]O\SY_]Vc% DO NOOZVc \OQ\O^ KXc SXMYX`OXSOXMO ^RS] WKc MK_]O cY_# KXN

^RKXU cY_ PY\ cY_\ _XNO\]^KXNSXQ%

BSXMO\OVc#

@K_V BMSZSYXS

@\O]SNOX^

Page 5: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

)635+(3 45(24 816 &$0 5$-( 51 2315(&5 8163 ,0)13/$5,10

&105$&5 .,45

)

,4F84G 0=E? "22=E<A -A1A4;4<A@ 1<3 *=B5H (1G $<5=?24;4<A =5 -E@>828=E@ "2BF8AH

"J 4 GI864PMFE4IT D84JPI8W R8 I86FDD8E7 K?4K TFP I8D4@E Q@>@C4EK 5T I8Q@8R@E> TFPI 466FPEK JK4K8D8EKJ 4E7 6I87@K

I8GFIKJ 6CFJ8CTY (9 TFP 78K86K 4ET JPJG@6@FPJ 46MQ@KT FE 4E 466FPEKW TFP J?FPC7 GIFDGKCT EFM9T K?8 <E4E6@4C @EJMKPMFE FI

6FDG4ET R@K? R?@6? K?8 466FPEK @J D4@EK4@E87Y 3FP 4CJF J?FPC7 GIFDGKCT I8GFIK 4ET 9I4P7PC8EK 46MQ@KT FI 4ET JPJG86K87

@E6@78E68 F9 @78EMKT K?8= KF GIFG8I C4R 8E9FI68D8EK 4PK?FI@M8JW TFPI JK4K8 4OFIE8T >8E8I4CW 4E7_FI K?8 &878I4C 0I4NO

4YWWS]]SYX !7C4"%

&EFM E> &H=<AJ 3=FEHJ

3FP D4T F5K4@E 4 9I88 6FGT F9 TFPI 6I87@K I8GFIK 9IFD 846? F9 K?8 K?I88 D4AFI 6I87@K I8GFIME> 4>8E6@8J FE68 8Q8IT ij

DFEK?J 5T Q@J@ME> ?OGX__RRRY4EEP4C6I87@KI8GFIKY6FD_# MKVVSXQ ^YVV$P\OO /..$*))$/))/# Y\ Lc MYDGC8ME> 4E "EEP4C $I87@K

AOZY\^ AO[_O]^ 7Y\W KXN WKSVSXQ S^ ^Y 2XX_KV 4\ONS^ AOZY\^ AO[_O]^ BO\`SMO# @%?% 3Yb (',)/(# 2^VKX^K# 82 *'*+/% FY_ MKX

Z\SX^ ^RS] PY\W K^ ?OGJX__RRRY4EEP4C6I87@KI8GFIKY6FD_6I4_I8HP8JLFID<E4CYG79% FY_ KV]Y MKX MYX^KM^ YXO YP ^RO PYVVYaSXQ

K?I88 E4MFE4C 6I87@K I8GFIME> 4>8E6@8JX

(GKA>9L

@%?% 3Yb (',/,(

2^VKX^K# 82 *'*+/

($/''$,),$-)/,

aaa%O[_SPKb%MYW

(LF=HA9D

@%?% 3Yb 0,*)

2VVOX# CE .,'(*

($///$*0.$*.+)

aaa%ObZO\SKX%MYW

5H9DI6DAED

@%?% 3Yb ('''

4RO]^O\# @2 (0'(-

($/..$*))$/))/

aaa%^\KX]_XSYX%MYW

)H== $DDK9B 3=FEHJ

@%?% 3Yb (',)/(

2^VKX^K# 82 *'*+/

($/..$*))$/))/

KXX_KVM\ONS^\OZY\^%MYW

)H9K< $B=HJ

3FP D4T R4EK KF 6FEJ@78I GC46@E> 4 9I4P7 4C8IK FE TFPI 6I87@K I8GFIKY "E @E@M4C 9I4P7 4C8IK @J 9I88 4E7 R@CC JK4T FE TFPI 6IONS^

<C8 9FI 4K C84JK mh 74TJY 0?8 4C8IK @E9FIDJ 6I87@KFIJ F9 GFJJ@5C8 9I4P7PC8EK 46MQ@KT R@K?@E TFPI I8GFIK 4E7 I8HP8JKJ K?4K KRO

M\ONS^Y\ MYX^KM^ cY_ Z\SY\ ^Y O]^KLVS]RSXQ KXc KMMY_X^] SX cY_\ XKWO% CY ZVKMO K P\K_N KVO\^ YX cY_\ M\ONS^ \OZY\^# MYX^KM^

4ET F9 K?8 K?I88 6I87@K I8GFIME> 4>8E6@8J @78EM<87 45FQ8Y "77@MFE4C @E9FID4MFE @J 4Q4@C45C8 4K

?OGX__RRRY4EEP4C6I87@KI8GFIKYMYW%

4=;KHAJM )H==N=

#5 964, &$ 9;(;,9A ?6< 0(=, ;0, 81/0; ;6 7<; ( 9,*<81;? -8,,@, 65 ?6<8 *8,+1; .3,B %019 >133 78,=,5; 5,> *8,+1; -864 ),15/

FG8E87 @E TFPI E4D8 R@K?FPK K?8 PJ8 F9 4 -(+ EPD58I K?4K @J @JJP87 KF TFP R?8E TFP @E@M4K8 K?8 9I88U8Y " J86PI@KT 9I88U8 @J

NO]SQXO7 KF GI8Q8EK GFK8EM4C 6I87@KFIJ 9IFD 4668JJ@E> TFPI 6I87@K I8GFIK R@K?FPK TFPI 6FEJ8EKY "J 4 I8JPCKW PJ@E> 4 J86PI@KT

-8,,@, 4(? 15;,8-,8, >1;0 68 +,3(? ?6<8 ()131;? ;6 6);(15 *8,+1;B '6< 4<9; 9,7(8(;,3? 73(*, ( 9,*<81;? -8,,@, 65 ?6<8 *8,+1; .3,

aS^R OK6? 6I87@K I8GFIME> 4>8E6TY (9 TFP I8HP8JK 4 J86PI@KT 9I88U8 9IFD 4 6FEJPD8I I8GFIME> 4>8E6T K?8I8 D4T 58 4 988 PG

KF fih KF GC468W C@= FI I8DFQ8 K?8 J86PI@KT 9I88U8Y (E FI78I KF GC468 4 J86PI@KT 9I88U8W TFP D4T 58 I8HP@I87 KF GIFQ@78 K?8

6FEJPD8I I8GFIME> 4>8E6T R@K? @E9FID4MFE K?4K @78EM<8J TFP @E6CP7@E> TFPI 9PCC E4D8W /F6@4C /86PI@KT EPD58IW 74K8 F9

LS\^R# M_\\OX^ KXN Z\O`SY_] KNN\O]]O]# K MYZc YP cY_\ ]^K^O$@JJP87 @78EM<64MFE 64I7W 4E7 4 I868EK PMC@KT 5@CCW 54EB JK4K8D8EK

Y\ SX]_\KXMO ]^K^OWOX^%

"338B=<19 %?44 ,4@=E?24@ =< '34<BAH .7461 3FP 64E F5K4@E @E9FID4MFE 9IFD K?8 6FEJPD8I I8GFIME> 4>8E6@8JW 7ONO\KV

0I478 $FDD@JJ@FE FI 9IFD TFPI I8JG86MQ8 JK4K8 "OFIE8T '8E8I4C 45FPK JK8GJ TFP 64E K4B8 KFR4I7 GI8Q8EME> @78EMKT K?8=Y

FY_ WKc I8GFIK JPJG86K87 @78EMKT K?8= KF CF64C C4R 8E9FI68D8EKW @E6CP7@E> KF K?8 &878I4C 0I478 $FDD@JJ@FE FI KF K?8

"OFIE8T '8E8I4C @E TFPI JK4K8Y .8J@78EKJ F9 *4ITC4E7W +FIK? $4IFC@E4W 4E7 .?F78 (JC4E7 64E F5K4@E DFI8 @E9FID4MFE 9IFD

K?8@I "OFIE8TJ '8E8I4C PJ@E> K?8 6FEK46K @E9FID4MFE 58CFRY

)=<=H9B 5H9<= &ECCAIIAED

-'' @OXX]cV`KXSK 2`O# >D

DK]RSXQ^YX# 54 )',/'

6FEJPD8IY=6Y>FQ# KXN

aaa%P^M%QY`&SN^ROP^

($/..$+*/$+**/

/9HMB9D< "D=?<4H &4<4?19

)'' B^% @K_V @VKMO

#4CMDFI8W *% jijhj

YKQ%]^K^O%WN%_]

($///$.+*$'')*

0EHJ@ &9HEBAD9 "D=?<4H

*=D=H9B

0''( =KSV BO\`SMO 4OX^O\

AKVOSQR# >4 ).-00

XMNYT%QY`

($/..$,--$.))-

3@E<= ,IB9D<

"D=?<4H &4<4?19

(,' BY_^R =KSX B^\OO^

@\Y`SNOXMO# A; ')0'*

?OGX__RRRYI@4>YI@Y>FQ

+'($).+$++''

DO aSVV 015 J8E7 TFP 4ET 8C86KIFE@6 6FDDPE@64MFEJ I8>4I7@E> K?@J @E6@78EK 4E7 4JB TFP KF 7@J6CFJ8 4ET G8IJFE4C

@E9FID4MFEY

Page 6: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

Page 1 ofof 3

/04,&( 0) '$4$ %2($&+

8PM]`L]d ))# )'(.

AY MPSLWQ ZQ 4W`PXP]N`]d# < LX b]T_TYR _Z TYQZ]X dZ` LMZ`_ L ]PNPY_ TYNTOPY_ TYaZWaTYR `YL`_SZ]TePO LNNP^^ ZQ [P]^ZYLW

TYQZ]XL_TZY LMZ`_ dZ`% JZ` XLd SLaP ]PNPTaPO _ST^ TYQZ]XL_TZY aTL LY PXLTW% HP ]PR]P_ _SL_ _ST^ TYNTOPY_ ZNN`]]PO LYO

L[[]PNTL_P dZ`] _TXP _Z ]PLO _ST^ WP__P]%

7+$4 +$11(/('#

AY 8PM]`L]d .# )'(.# bP bP]P TYQZ]XPO _SL_ 3[_Z^# Z`] QZ]XP] OTRT_LW [WL_QZ]X []ZaTOP]# Pc[P]TPYNPO L ^PN`]T_d

TYNTOPY_ WL^_ dPL] _SL_ TYaZWaPO NP]_LTY ZQ T_^ ]P_LTW N`^_ZXP]^h bPM^T_P^# TYNW`OTYRTYNTOPY_ WL^_ dPL] _SL_ TYaZWaPO NP]_LTY ZQ T_^ ]P_LTW N`^_ZXP]^h bPM^T_P^# TYNW`OTYR bbb%MW`PXP]N`]d%NZX% 3[_Z^

SL^ TYOTNL_PO TY_]`^TZY^ _Z ^ZXP ZQ _SPT] ^d^_PX^ MPRLY TY 8PM]`L]d )'(-)'(- LYO PYOPOLYO PYOPO TY 6PNPXMP] )'(-% 6`]TYR

_SL_ _TXP# bP `YOP]^_LYO _SL_ NdMP] N]TXTYLW^ [WLNPO XLWbL]P ZY 3[_Z^h ^P]aP]^NdMP] N]TXTYLW^ [WLNPO XLWbL]P ZY 3[_Z^h ^P]aP]^ LYO RLTYPO `YL`_SZ]TePO LNNP^^

_Z 4W`PXP]N`]dh^ OL_L% 3W_SZ`RS bP PYOPO Z`] ]PWL_TZY^ST[ bT_S 3[_Z^ TY DP[_PXMP] )'(-# bP SLaP MPPY L^^`]POOL_L% 3W_SZ`RS bP PYOPO Z`] ]PWL_TZY^ST[ bT_S 3[_Z^ TY DP[_PXMP] )'(-# bP SLaP MPPY L^^`]PO

_SL_ _SP XLWbL]P SL^ MPPY ]PXZaPO LYO _SL_ _SP N]TXTYLW^ YZ WZYRP] SLaP LNNP^^ _Z _SPT] ^d^_PX^ Z] OL_L%_SL_ _SP XLWbL]P SL^ MPPY ]PXZaPO LYO _SL_ _SP N]TXTYLW^ YZ WZYRP] SLaP LNNP^^ _Z _SPT] ^d^_PX^ Z] OL_L%_SL_ _SP XLWbL]P SL^ MPPY ]PXZaPO LYO _SL_ _SP N]TXTYLW^ YZ WZYRP] SLaP LNNP^^ _Z _SPT] ^d^_PX^ Z] OL_L%

3[_Z^ OTO YZ_ OT^NZaP] _SP TY_]`^TZY `Y_TW @ZaPXMP] )/# )'(-% HP `YOP]^_LYO _SL_ 3[_Z^ NZY_LN_PO 8POP]LW WLb@ZaPXMP] )/# )'(-% HP `YOP]^_LYO _SL_ 3[_Z^ NZY_LN_PO 8POP]LW WLb@ZaPXMP] )/# )'(-% HP `YOP]^_LYO _SL_ 3[_Z^ NZY_LN_PO 8POP]LW WLb

PYQZ]NPXPY_ LRPYNTP^ LYO _SP F%D% 6P[L]_XPY_ ZQ =`^_TNP L_ _SL_ _TXP% HP LW^Z `YOP]^_LYO _SL_PYQZ]NPXPY_ LRPYNTP^ LYO _SP F%D% 6P[L]_XPY_ ZQ =`^_TNP L_ _SL_ _TXP% HP LW^Z `YOP]^_LYO _SL_PYQZ]NPXPY_ LRPYNTP^ LYO _SP F%D% 6P[L]_XPY_ ZQ =`^_TNP L_ _SL_ _TXP% HP LW^Z `YOP]^_LYO _SL_ 3[_Z^ bL^

]P\`P^_PO Md WLb PYQZ]NPXPY_ _Z OPWLd YZ_TQdTYR T_^ ]P_LTWP] N`^_ZXP]^# TYNW`OTYR 4W`PXP]N`]d# ^Z L^ YZ_ _Z TY_P]QP]P]P\`P^_PO Md WLb PYQZ]NPXPY_ _Z OPWLd YZ_TQdTYR T_^ ]P_LTWP] N`^_ZXP]^# TYNW`OTYR 4W`PXP]N`]d# ^Z L^ YZ_ _Z TY_P]QP]P]P\`P^_PO Md WLb PYQZ]NPXPY_ _Z OPWLd YZ_TQdTYR T_^ ]P_LTWP] N`^_ZXP]^# TYNW`OTYR 4W`PXP]N`]d# ^Z L^ YZ_ _Z TY_P]QP]P

bT_S _SPT] ZYRZTYR TYaP^_TRL_TZY% HP LW^Z `YOP]^_LYO _SL_ WLb PYQZ]NPXPY_ NZY_TY`P^ _Z TYaP^_TRL_P _ST^ TYNTOPY_%HP LW^Z `YOP]^_LYO _SL_ WLb PYQZ]NPXPY_ NZY_TY`P^ _Z TYaP^_TRL_P _ST^ TYNTOPY_%HP LW^Z `YOP]^_LYO _SL_ WLb PYQZ]NPXPY_ NZY_TY`P^ _Z TYaP^_TRL_P _ST^ TYNTOPY_%HP LW^Z `YOP]^_LYO _SL_ WLb PYQZ]NPXPY_ NZY_TY`P^ _Z TYaP^_TRL_P _ST^ TYNTOPY_%

7+$4 ,/)02.$4,0/ 7$3 ,/60-6('#

3[_Z^ SL^ TYQZ]XPO `^ _SL_ L__LNVP]^ SLO LNNP^^ _Z OL_L L^^ZNTL_PO bT_S L[[]ZcTXL_PWd ,+#''' NWTPY_ Z]OP]^ XLOP3[_Z^ SL^ TYQZ]XPO `^ _SL_ L__LNVP]^ SLO LNNP^^ _Z OL_L L^^ZNTL_PO bT_S L[[]ZcTXL_PWd ,+#''' NWTPY_ Z]OP]^ XLOP3[_Z^ SL^ TYQZ]XPO `^ _SL_ L__LNVP]^ SLO LNNP^^ _Z OL_L L^^ZNTL_PO bT_S L[[]ZcTXL_PWd ,+#''' NWTPY_ Z]OP]^ XLOP

MPQZ]P DP[_PXMP] ()# )'(- _Z TYNW`OP1 8T]^_ LYO >L^_>L^_ @LXP2 3OO]P^^2 BSZYP @`XMP]2@LXP2 3OO]P^^2 BSZYP @`XMP]2@LXP2 3OO]P^^2 BSZYP @`XMP]2 7XLTW2 3OO]P^^2 LYO 6PMT_ Z]

5]POT_ 5L]O @`XMP] bT_S Pc[T]L_TZY OL_P^% 3[_Z^ SL^ TYOTNL_PO _SL_ YZ 5]POT_ GP]TQTNL_TZY GLW`P^ !5GG" Z] DZNTLWPc[T]L_TZY OL_P^% 3[_Z^ SL^ TYOTNL_PO _SL_ YZ 5]POT_ GP]TQTNL_TZY GLW`P^ !5GG" Z] DZNTLWPc[T]L_TZY OL_P^% 3[_Z^ SL^ TYOTNL_PO _SL_ YZ 5]POT_ GP]TQTNL_TZY GLW`P^ !5GG" Z] DZNTLWPc[T]L_TZY OL_P^% 3[_Z^ SL^ TYOTNL_PO _SL_ YZ 5]POT_ GP]TQTNL_TZY GLW`P^ !5GG" Z] DZNTLW

DPN`]T_d @`XMP]^ !DD@" L^^ZNTL_PO bT_S 4W`PXP]N`]d NWTPY_^ bP]P ]P_LTYPO Z] LNNP^^PO%DPN`]T_d @`XMP]^ !DD@" L^^ZNTL_PO bT_S 4W`PXP]N`]d NWTPY_^ bP]P ]P_LTYPO Z] LNNP^^PO%DPN`]T_d @`XMP]^ !DD@" L^^ZNTL_PO bT_S 4W`PXP]N`]d NWTPY_^ bP]P ]P_LTYPO Z] LNNP^^PO%

7+$4 $2( 7( '0,/*#

HP PYOPO Z`] ]PWL_TZY^ST[ bT_S 3[_Z^ TY DP[_PXMP] )'(- QZ] `Y]PWL_PO ]PL^ZY^% HP SLaP MPPY bZ]VTYR bT_SHP PYOPO Z`] ]PWL_TZY^ST[ bT_S 3[_Z^ TY DP[_PXMP] )'(- QZ] `Y]PWL_PO ]PL^ZY^% HP SLaP MPPY bZ]VTYR bT_SHP PYOPO Z`] ]PWL_TZY^ST[ bT_S 3[_Z^ TY DP[_PXMP] )'(- QZ] `Y]PWL_PO ]PL^ZY^% HP SLaP MPPY bZ]VTYR bT_SHP PYOPO Z`] ]PWL_TZY^ST[ bT_S 3[_Z^ TY DP[_PXMP] )'(- QZ] `Y]PWL_PO ]PL^ZY^% HP SLaP MPPY bZ]VTYR bT_S

3[_Z^ _Z WPL]Y XZ]P LMZ`_ _SP TYNTOPY_% 3[_Z^ SL^ TYOTNL_PO T_ ]P_LTYPO L WPLOTYR NdMP]^PN`]T_d QT]X _Z ]PXZaP _SP3[_Z^ _Z WPL]Y XZ]P LMZ`_ _SP TYNTOPY_% 3[_Z^ SL^ TYOTNL_PO T_ ]P_LTYPO L WPLOTYR NdMP]^PN`]T_d QT]X _Z ]PXZaP _SP3[_Z^ _Z WPL]Y XZ]P LMZ`_ _SP TYNTOPY_% 3[_Z^ SL^ TYOTNL_PO T_ ]P_LTYPO L WPLOTYR NdMP]^PN`]T_d QT]X _Z ]PXZaP _SP3[_Z^ _Z WPL]Y XZ]P LMZ`_ _SP TYNTOPY_% 3[_Z^ SL^ TYOTNL_PO T_ ]P_LTYPO L WPLOTYR NdMP]^PN`]T_d QT]X _Z ]PXZaP _SP

XLWbL]P Q]ZX T_^ ^d^_PX^ LYO T^ LN_TaPWd XZYT_Z]TYR _SP [WL_QZ]X _Z ^LQPR`L]O TYQZ]XL_TZY%XLWbL]P Q]ZX T_^ ^d^_PX^ LYO T^ LN_TaPWd XZYT_Z]TYR _SP [WL_QZ]X _Z ^LQPR`L]O TYQZ]XL_TZY%XLWbL]P Q]ZX T_^ ^d^_PX^ LYO T^ LN_TaPWd XZYT_Z]TYR _SP [WL_QZ]X _Z ^LQPR`L]O TYQZ]XL_TZY%XLWbL]P Q]ZX T_^ ^d^_PX^ LYO T^ LN_TaPWd XZYT_Z]TYR _SP [WL_QZ]X _Z ^LQPR`L]O TYQZ]XL_TZY% HP SLaP TY^_]`N_PO

3[_Z^ _Z OP^_]Zd LYd LYO LWW ]PXLTYTYR 4W`PXP]N`]d NWTPY_ OL_L%3[_Z^ _Z OP^_]Zd LYd LYO LWW ]PXLTYTYR 4W`PXP]N`]d NWTPY_ OL_L%3[_Z^ _Z OP^_]Zd LYd LYO LWW ]PXLTYTYR 4W`PXP]N`]d NWTPY_ OL_L%

7+$4 &$/ 805 '0#7+$4 &$/ 805 '0#

JZ` ^SZ`WO ]PXLTY aTRTWLY_ QZ] TYNTOPY_^ ZQ Q]L`O LYO TOPY_T_d _SPQ_ Md ]PR`WL]Wd ]PaTPbTYR dZ`] LNNZ`Y_ ^_L_PXPY_^JZ` ^SZ`WO ]PXLTY aTRTWLY_ QZ] TYNTOPY_^ ZQ Q]L`O LYO TOPY_T_d _SPQ_ Md ]PR`WL]Wd ]PaTPbTYR dZ`] LNNZ`Y_ ^_L_PXPY_^JZ` ^SZ`WO ]PXLTY aTRTWLY_ QZ] TYNTOPY_^ ZQ Q]L`O LYO TOPY_T_d _SPQ_ Md ]PR`WL]Wd ]PaTPbTYR dZ`] LNNZ`Y_ ^_L_PXPY_^

LYO XZYT_Z]TYR N]POT_ ]P[Z]_^% HP ]PNZXXPYO dZ` TXXPOTL_PWd NZY_LN_ dZ`] N]POT_ Z] OPMT_ NL]O NZX[LYd LYOLYO XZYT_Z]TYR N]POT_ ]P[Z]_^% HP ]PNZXXPYO dZ` TXXPOTL_PWd NZY_LN_ dZ`] N]POT_ Z] OPMT_ NL]O NZX[LYd LYO

TYQZ]X _SPX _SL_ dZ`] NL]O TYQZ]XL_TZY XLd SLaP MPPY NZX[]ZXT^PO% JZ`] MLYV Z] N]POT_ NL]O []ZaTOP] bTWWTYQZ]X _SPX _SL_ dZ`] NL]O TYQZ]XL_TZY XLd SLaP MPPY NZX[]ZXT^PO% JZ`] MLYV Z] N]POT_ NL]O []ZaTOP] bTWW

^`RRP^_ L[[]Z[]TL_P ^_P[^ _Z []Z_PN_ dZ`] LNNZ`Y_% JZ` ^SZ`WO ]PaTPb dZ`] MLYV LYO NL]O ^_L_PXPY_^ ]PR WL]Wd# LYO^`RRP^_ L[[]Z[]TL_P ^_P[^ _Z []Z_PN_ dZ`] LNNZ`Y_% JZ` ^SZ`WO ]PaTPb dZ`] MLYV LYO NL]O ^_L_PXPY_^ ]PR WL]Wd# LYO

TXXPOTL_PWd ]P[Z]_ LYd^`^[TNTZ`^ LN_TaT_d _Z dZ`] MLYV Z] N]POT_ NL]O []ZaTOP]%TXXPOTL_PWd ]P[Z]_ LYd^`^[TNTZ`^ LN_TaT_d _Z dZ`] MLYV Z] N]POT_ NL]O []ZaTOP]% BLdXPY_ NL]O ]`WP^ RPYP]LWWd []ZaTOP

_SL_ NL]OSZWOP]^ L]P YZ_ ]P^[ZY^TMWP QZ] `YL`_SZ]TePO NSL]RP^ ]P[Z]_PO TY L _TXPWd XLYYP]%

HP L_ 4W`PXP]N`]d aLW`P Z`] NWTPY_ ]PWL_TZY^ST[# L[[]PNTL_P dZ`] M`^TYP^^ LYO bZ`WO WTVP _Z []ZaTOP L^ X`NS

L^^T^_LYNP L^ bP NLY% =`^_ WTVP T_ T^ L RZZO []LN_TNP _Z XZYT_Z] dZ`] MLYV LNNZ`Y_^# T_ T^ L RZZO []LN_TNP _Z XZYT_Z] dZ`]

TOPY_T_d% ESP]PQZ]P# L^ LY LOOT_TZYLW ^P]aTNP QZ] Z`] NWTPY_^# bP SLaP L]]LYRPO _Z SLaP 3WW5WPL] <6 !bbb%LWWNWPL]TO%NZX"

[]ZaTOP TOPY_T_d []Z_PN_TZY ^`[[Z]_ QZ] () XZY_S^ L_ YZ NZ^_ _Z dZ`% 3WW5WPL] <6h^ <OPY_T_d CP[LT] ^P]aTNP^ L]P LaLTWLMWP

_Z dZ` ^_L]_TYR ZY _SP OL_P ZQ _ST^ YZ_TNP LYO NLY MP `^PO L_ LYd _TXP O`]TYR _SP YPc_ () XZY_S^% EST^ ^P]aTNP T^

L`_ZXL_TNLWWd LaLTWLMWP _Z dZ` bT_S YZ PY]ZWWXPY_ ]P\`T]PO% 3^ dZ` XZYT_Z] dZ`] N]POT_# TQ dZ` ^[Z_ L []ZMWPX# ^TX[Wd

NLWW 3WW5WPL] <6 L_ ($/,,$**-$--//# []ZaTOP dZ`] CPQP]PYNP 5ZOP fCPQP]PYNPK5ZOPg LYO L OPOTNL_PO TYaP^_TRL_Z] bTWW SPW[

]PNZaP] QTYLYNTLW WZ^^P^# ]P^_Z]P dZ`] N]POT_ LYO XLVP ^`]P dZ`] TOPY_T_d T^ ]P_`]YPO _Z T_^ []Z[P] NZYOT_TZY%

Page 7: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

Page 2 of 3

&0/4$&4,/* 4+( )('(2$- 42$'( &0..,33,0/" -$7 (/)02&(.(/4 ! 4+( &2(',4 %52($53

<Y LOOT_TZY# dZ` XLd NZY_LN_ _SP 8POP]LW E]LOP 5ZXXT^^TZY !i8E5j"# dZ`] ^_L_Ph^ 3__Z]YPd 9PYP]LWh^ ZQQTNP# Z] WLb

PYQZ]NPXPY_# _Z ]P[Z]_ TYNTOPY_^ ZQ TOPY_T_d _SPQ_ Z] _Z WPL]Y LMZ`_ ^_P[^ dZ` NLY _LVP _Z []Z_PN_ dZ`]^PWQ Q]ZX TOPY_T_d

_SPQ_% EZ WPL]Y XZ]P# dZ` NLY RZ _Z _SP 8E5h^ bPM^T_P L_ bbb%NZY^`XP]%RZa&TO_SPQ_2 NLWW _SP 8E5 L_ !/.." <6E;78E !+*/$

+**/"2 Z] b]T_P _Z1 8E5 5ZY^`XP] CP^[ZY^P 5PY_P]# -'' BPYY^dWaLYTL 3aPY`P# @H# HL^STYR_ZY# 65 )',/'%

JZ` XLd LW^Z [P]TZOTNLWWd ZM_LTY N]POT_ ]P[Z]_^ Q]ZX PLNS YL_TZYbTOP N]POT_ ]P[Z]_TYR LRPYNd% <Q dZ` OT^NZaP]

TYQZ]XL_TZY ZY dZ`] N]POT_ ]P[Z]_ L]T^TYR Q]ZX L Q]L`O`WPY_ _]LY^LN_TZY# dZ` ^SZ`WO ]P\`P^_ _SL_ _SP N]POT_ ]P[Z]_TYR

LRPYNd OPWP_P _SL_ TYQZ]XL_TZY Q]ZX dZ`] N]POT_ ]P[Z]_ QTWP% <Y LOOT_TZY# `YOP] QPOP]LW WLb# dZ` L]P PY_T_WPO _Z ZYP Q]PP

NZ[d ZQ dZ`] N]POT_ ]P[Z]_ PaP]d () XZY_S^ Q]ZX PLNS ZQ _SP _S]PP YL_TZYbTOP N]POT_ ]P[Z]_TYR LRPYNTP^% JZ` XLd

ZM_LTY L Q]PP NZ[d ZQ dZ`] N]POT_ ]P[Z]_ Md RZTYR _Z bbb%3YY`LW5]POT_CP[Z]_%NZX Z] Md NLWWTYR !/.." *))$/))/% JZ`

XLd NZY_LN_ _SP YL_TZYbTOP N]POT_ ]P[Z]_TYR LRPYNTP^ L_1

7\`TQLc 7c[P]TLY E]LY^FYTZY

!/''" ,),$-)/, !///" *0.$*.+) !/''" 0(-$//''

B%A% 4Zc .+')+( B%A% 4Zc 0.'( 8]L`O GTN_TX 3^^T^_LYNP 6TaT^TZY

3_WLY_L# 93 *'*.+$')+( 3WWPY# EI .,'(* B%A% 4Zc )'''

bbb%P\`TQLc%NZX bbb%Pc[P]TLY%NZX 5SP^_P]# B3 (0'))

bbb%_]LY^`YTZY%NZX

JZ` XLd ZM_LTY LOOT_TZYLW TYQZ]XL_TZY Q]ZX _SP 8E5 LYO _SP N]POT_ ]P[Z]_TYR LRPYNTP^ LMZ`_ Q]L`O LWP]_^ LYO ^PN`]T_d

Q]PPeP^% JZ` NLY LOO L Q]L`O LWP]_ _Z dZ`] N]POT_ ]P[Z]_ QTWP _Z SPW[ []Z_PN_ dZ`] N]POT_ TYQZ]XL_TZY% 3 Q]L`O LWP]_ NLY

XLVP T_ XZ]P OTQQTN`W_ QZ] ^ZXPZYP _Z RP_ N]POT_ TY dZ`] YLXP MPNL`^P T_ _PWW^ N]POT_Z]^ _Z QZWWZb NP]_LTY []ZNPO`]P^ _Z

[]Z_PN_ dZ`# M`_ T_ LW^Z XLd OPWLd dZ`] LMTWT_d _Z ZM_LTY N]POT_% JZ` XLd [WLNP L Q]L`O LWP]_ TY dZ`] QTWP Md NLWWTYR U`^_ ZYP

ZQ _SP _S]PP YL_TZYbTOP N]POT_ ]P[Z]_TYR LRPYNTP^ WT^_PO LMZaP% 3^ ^ZZY L^ _SL_ LRPYNd []ZNP^^P^ dZ`] Q]L`O LWP]_# T_ bTWW

YZ_TQd _SP Z_SP] _bZ LRPYNTP^# bSTNS _SPY X`^_ LW^Z [WLNP Q]L`O LWP]_^ TY dZ`] QTWP% <Y LOOT_TZY# dZ` NLY NZY_LN_ _SP

YL_TZYbTOP N]POT_ ]P[Z]_TYR LRPYNTP^ L_ _SP QZWWZbTYR Y`XMP]^ _Z [WLNP L ^PN`]T_d Q]PPeP _Z ]P^_]TN_ LNNP^^ _Z dZ`] N]POT_

]P[Z]_1

(1) 7\`TQLc k !/''" *+0$00-'

(2) 7c[P]TLY k !///" *0.$*.+)

(3) E]LY^FYTZY k !///" 0'0$//.)

JZ` bTWW YPPO _Z ^`[[Wd dZ`] YLXP# LOO]P^^# OL_P ZQ MT]_S# DZNTLW DPN`]T_d Y`XMP] LYO Z_SP] [P]^ZYLW TYQZ]XL_TZY% ESP

QPP _Z [WLNP L N]POT_ Q]PPeP aL]TP^ ML^PO ZY bSP]P dZ` WTaP% 3Q_P] ]PNPTaTYR dZ`] ]P\`P^_# PLNS N]POT_ ]P[Z]_TYR LRPYNd

bTWW ^PYO dZ` L NZYQT]XL_TZY WP__P] NZY_LTYTYR L `YT\`P B<@ Z] [L^^bZ]O _SL_ dZ` bTWW YPPO _Z WTQ_ Z] ]PXZaP _SP Q]PPeP%

JZ` ^SZ`WO VPP[ _SP B<@ Z] [L^^bZ]O TY L ^LQP [WLNP%

)02 .02( ,/)02.$4,0/

HP ]PR]P_ LYd TYNZYaPYTPYNP Z] NZYNP]Y _ST^ TYNTOPY_ XLd NL`^P dZ`% BWPL^P OZ YZ_ SP^T_L_P _Z NZY_LN_ Z`] ^`[[Z]_

LRPY_^ QZ] _ST^ PaPY_ L_ ($/,,$**-$--// TQ dZ` SLaP LYd \`P^_TZY^ Z] NZYNP]Y^%

DTYNP]PWd#

4P]YL]O 8% >ZN]LQ_#

5Z][Z]L_P 5ZY_]ZWWP]

4W`PXP]N`]d# <YN

$#$# 7AG<EDGAD (J= 17" !&##"

79G@AD?HED" *AGHFA<H E> )EBIC;A9 %###&

Page 8: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

Page 3 of 3

$'',4,0/$- ,/)02.$4,0/ )02 30.( 34$4(3

., 826 (3+ (1 .27( 3+4.*+15' JZ` XLd NZY_LN_ WZNLW WLb PYQZ]NPXPY_ Z] _SP <ZbL 3__Z]YPd 9PYP]LWh^ AQQTNP _Z ]P[Z]_

^`^[PN_PO TYNTOPY_^ ZQ TOPY_T_d _SPQ_% JZ` NLY NZY_LN_ _SP <ZbL 3__Z]YPd 9PYP]LW L_1

AQQTNP ZQ _SP 3__Z]YPd 9PYP]LW

(*', 7% HLWY`_ D_]PP_

6P^ ?ZTYP^# <3 ,'*(0

!,(," )/($,(-+

S__[1&&bbb%TZbLL__Z]YPdRPYP]LW%RZa&

., 826 (3+ ( 0(38/(1* 3+4.*+15' JZ` XLd ZM_LTY TYQZ]XL_TZY LMZ`_ LaZTOTYR TOPY_T_d _SPQ_ Q]ZX _SP 8E5 Z] _SP

?L]dWLYO 3__Z]YPd 9PYP]LWh^ AQQTNP% ESP^P ZQQTNP^ NLY MP ]PLNSPO L_1

8POP]LW E]LOP 5ZXXT^^TZY AQQTNP ZQ _SP 3__Z]YPd 9PYP]LW

5ZY^`XP] CP^[ZY^P 5PY_P] 5ZY^`XP] B]Z_PN_TZY 6TaT^TZY

-'' BPYY^dWaLYTL 3aPY`P# @H )'' D_% BL`W BWLNP

HL^STYR_ZY# 65 )',/' 4LW_TXZ]P# ?6 )()')

!/.." <6E;78E !+*/$+**/" !///" .+*$'')*

S__[1&&bbb%Q_N%RZa&TO_SPQ_& bbb%ZLR%^_L_P%XO%`^

., 826 (3+ ( 1235- )(32/.1( 3+4.*+15' JZ` XLd ZM_LTY TYQZ]XL_TZY LMZ`_ []PaPY_TYR TOPY_T_d _SPQ_ Q]ZX _SP 8E5 Z]

_SP @Z]_S 5L]ZWTYL 3__Z]YPd 9PYP]LWh^ AQQTNP% ESP^P ZQQTNP^ NLY MP ]PLNSPO L_1

8POP]LW E]LOP 5ZXXT^^TZY @Z]_S 5L]ZWTYL 6P[L]_XPY_ ZQ =`^_TNP

5ZY^`XP] CP^[ZY^P 5PY_P] 3__Z]YPd 9PYP]LW CZd 5ZZ[P]

-'' BPYY^dWaLYTL 3aPY`P# @H 0''( ?LTW DP]aTNP 5PY_P]

HL^STYR_ZY# 65 )',/' CLWPTRS# @5 ).-00$0''(

!/.." <6E;78E !+*/$+**/" !/.." ,--$.))-

bbb%NZY^`XP]%RZa&TO_SPQ_ S__[1&&bbb%YNOZU%NZX

., 826 (3+ ( 3-2*+ .4/(1* 3+4.*+15' BWPL^P NZY_LN_ ^_L_P Z] WZNLW WLb PYQZ]NPXPY_ _Z OP_P]XTYP bSP_SP] dZ` NLY

QTWP Z] ZM_LTY L [ZWTNP ]P[Z]_ TY ]PRL]O _Z _ST^ TYNTOPY_% <Y LOOT_TZY# dZ` NLY NZY_LN_ _SP CSZOP <^WLYO 3__Z]YPd 9PYP]LW

L_1

AQQTNP ZQ _SP 3__Z]YPd 9PYP]LW

(,' DZ`_S ?LTY D_]PP_

B]ZaTOPYNP# CSZOP <^WLYO ')0'*

!+'(" ).+$++''

S__[1&&bbb%]TLR%]T%RZa&

Page 9: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

<=B835 =6 41B1 2@5137

4HDU 3XVWRPHU/

3HQWXU\ ZDV LQIRUPHG RQ 6HEUXDU\ -WK# (&', E\ RXU )

UG>DUW\ 5FRPPHUFH >URYLGHU !1SWRV" WKDW WKHLU VRIWZDUH

SODWIRUP ZKLFK KRVWV FHQWXU\PDUWLDODUWV%FRP H[SHULHQFHG D GDWD EUHDFK% BKH LQYHVWLJDWLRQ E\ 1SWRV DQG WKH 628 3\EHU

3ULPHV 4LYLVLRQ LQGLFDWHV WKH LQWUXVLRQ EHJDQ LQ 6HEUXDU\ (&'+ DQG HQGHG LQ 4HFHPEHU (&'+% 4XULQJ WKLV WLPH WKH

DWWDFNHUV JDLQHG DFFHVV WR FXVWRPHU LQIRUPDWLRQ% BR GDWH ZH KDYH QR FRQILUPDWLRQ WKDW DQ\ FDUG RU SHUVRQDO GDWD KDV

EHHQ PLVXVHG% 1V D SUHFDXWLRQDU\ VWHS 1SWRV ZRUNHG ZLWK ODZ HQIRUFHPHQW WR SURYLGH WKH QXPEHUV RI WKH DIIHFWHG

FDUGV WR WKH LVVXHUV IRU DGGLWLRQDO VHFXULW\ PRQLWRULQJ%

CKDW 8QIRUPDWLRQ CDV 8QYROYHG0

BKH LQIRUPDWLRQ WKH DWWDFNHU KDG DFFHVV WR ZDV ILUVW DQG ODVW QDPH# DGGUHVV# SKRQH QXPEHU DQG DQ\ FUHGLW RU

GHELW FDUG QXPEHUV ZLWK H[SLUDWLRQ GDWHV%

CKDW 8V 2HLQJ 4RQH BR AHFXUH BKH >ODWIRUP0

=XU )UG

>DUW\ >URYLGHU KLUHG ;DQGLDQW# D OHDGLQJ F\EHUVHFXULW\ ILUP# ZKLFK FRPSOHWHG WKH UHPRYDO RI WKH

PDOZDUH IURP WKHLU VHUYHUV DQG FRQWLQXHV WR DFWLYHO\ PRQLWRU WKHLU SODWIRUP WR VDIHJXDUG SHUVRQDO LQIRUPDWLRQ JRLQJ

IRUZDUG% 1SWRV LV DOVR IXOO\ FRRSHUDWLQJ ZLWK IHGHUDO ODZ HQIRUFHPHQW LQ DQ HIIRUW WR EULQJ WR MXVWLFH WKH SHUSHWUDWRU%

CKDW CH @HFRPPHQG BR =XU 3XVWRPHUV/

BR SURWHFW \RXUVHOI IURP WKH SRVVLELOLW\ RI LGHQWLW\ RU FUHGLW FDUG WKHIW ZH UHFRPPHQG \RX LPPHGLDWHO\ FRQWDFW

\RXU FUHGLW RU GHELW FDUG FRPSDQ\ DQG LQIRUP WKHP WKDW \RXU FDUG LQIRUPDWLRQ PD\ KDYH EHHQ FRPSURPLVHG VR WKH\ FDQ

LVVXH \RX D UHSODFHPHQW FDUG% 1OVR SOHDVH UHYLHZ \RXU EDQNLQJ DQG FUHGLW FDUG VWDWHPHQWV DQG UHSRUW DQ\ VXVSLFLRXV

DFWLYLW\ WR WKH UHOHYDQW ILQDQFLDO LQVWLWXWLRQV%

3HQWXU\]V >URPLVH BR =XU 3XVWRPHUV

CH GHHSO\ UHJUHW WKLV EUHDFK RFFXUUHG GHVSLWH WKH PDQ\ VHFXULW\ VDIHJXDUGV ZKLFK DUH LQ SODFH% =QFH DJDLQ ZH

KDYH EHHQ DVVXUHG E\ 1SWRV WKDW WKLV LVVXH KDV EHHQ UHVROYHG DQG RXU VLWH LV VHFXUH IRU IXWXUH WUDQVDFWLRQV%

CH DUH FRPPLWWHG WR VHFXUH \RXU SHUVRQDO LQIRUPDWLRQ E\ KROGLQJ RXU YHQGRUV WR WKH KLJKHVW EXVLQHVV VWDQGDUGV%

6RU ?XHVWLRQV =U ;RUH 8QIRUPDWLRQ

8I \RX KDYH DQ\ TXHVWLRQV RU LI ZH FDQ DVVLVW \RX LQ DQ\ ZD\# SOHDVH FDOO '$-,,$(,($'.&( ;RQGD\ WKURXJK

BKXUVGD\ EHWZHHQ WKH KRXUV RI -/&& DP DQG */&& SP 3HQWUDO BLPH%

ALQFHUHO\#

>DXO CHEE

>UHVLGHQW# 3HQWXU\ 993

Page 10: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

*(*+ 572393723713 18663;13 0?37>3& <>5=3 3

60==43@<& 71 */)(,

.(+'-*/'...(

February 21, 2017

[Customer Name][Customer Address][Customer Address]

NOTICE OF DATA BREACH

Dear Customer:

We are writing to you because of an incident involving access to information associated withonline purchases made on our website www.MovieMars.com. Although we are unaware of anyactual misuse of your information, we are providing notice to you and other potentially affectedcustomers about the incident, and about tools you can use to protect yourself against possibleidentity theft or fraud.

What Happened?

The MovieMars.com site is operated by a third-party company, Aptos, Inc. (our “platformprovider”). We were informed on February 6, 2017 that the platform provider’s systemsexperienced an intrusion last year. The intruder or intruders placed malware on the platformprovider’s services, and by doing so gained access to our customers’ payment card data. Todate, the investigation indicates that the intrusion began in approximately February 2016 andended in December 2016. The attackers gained access to customer information includingpayment card numbers as customers made transactions on the platform provider’s systems, andhad access to historical payment card data. Because you have provided your payment cardinformation to us in the past, we are notifying you about this data breach.

You may wonder why you are hearing about the breach now. The platform provider did notdiscover the breach until November 2016. In addition, law enforcement is investigating, andasked that notification to customers be delayed to allow the investigation to move forward.

What Information Was Involved?

The information that the attacker had access to includes your first and last name, address, phonenumber, and any debit or credit card numbers with expiration dates you may have used on ourwebsite.

Page 11: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

What Are We Doing?

Our platform provider has worked with a leading cybersecurity firm to remove the malware fromits systems and is actively monitoring the platform to safeguard personal information. Ourplatform provider has also contacted and offered its cooperation to federal law enforcement.

What You Can Do

Please be sure to review the enclosed “Additional Resources” section included with this letter.This section describes some additional steps you can take to help protect yourself (such asobtaining a copy of your credit report, or placing a security freeze on your credit report) andprovides important contact information for the Federal Trade Commission, other lawenforcement agencies, and credit reporting agencies.

In addition, we recommend you consider the following:

" Contact Your Credit or Debit Card Issuer. While we have taken steps to notify creditcard processors, we recommend that you also immediately notify your credit card issuingbank and follow its advice with regard to your credit card.

" Regularly Review Your Financial Statements. We recommend you remain vigilant byregularly reviewing your credit card and bank account statements and monitoring freecredit reports; and immediately alert your credit card issuing bank of any suspiciouscharges. This is one of the most important steps that you can take to detect and preventany unauthorized use of your credit card number.

" Be Aware of online “Phishing” Schemes. You should also always be on the lookout forphishing schemes – emails where fraudsters pose as legitimate companies in order totrick people into disclosing personal information or clicking a link that causes theinstallation of malware. Any email correspondence we may send regarding this matterwill not contain any clickable hyperlinks and will not ask you to reply with personalinformation. Never provide sensitive information to unsolicited requests claiming tocome from us, your bank, or other organizations.

For More Information

We sincerely regret that this incident happened, and will continue to put the right measures inplace to maintain the security of your information. For more information on preventing identitytheft, please review the “Additional Resources” section.

Page 12: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

ADDITIONAL RESOURCES

Obtain a Free Credit Report. We also recommend you remain vigilant by obtaining andreviewing your credit report. You may request a free copy of your U.S. credit report once every12 months by visiting www.annualcreditreport.com or by calling 1-877-322-8228 toll free. Youcan print a copy of the request form at https://www.consumer.ftc.gov/articles/pdf-0093-annual-report-request-form.pdf. You should review this for any information that is not accurate.

When you receive your credit reports, review them carefully. Look for accounts or creditorinquiries that you did not initiate or do not recognize. Look for information, such as homeaddress and Social Security number, that is not accurate. If you see anything you do notunderstand, call the credit reporting agency at the telephone number on the report.

Information on Credit Report Fraud Alerts. You also may place a fraud alert on your creditfile. A fraud alert tells creditors to contact you before they open any new accounts or changeyour existing accounts. Call any one of the three major credit bureaus. As soon as one creditbureau confirms your fraud alert, the others are notified to place fraud alerts.

Equifax Experian TransUnionPhone 1-800-525-6285 or

1-888-766-00081-888-397-3742 1-800-680-7289

Address Equifax Consumer FraudDivision P.O. Box 740256Atlanta, GA 30374

Experian Fraud DivisionP.O. Box 9554Allen, TX 75013

TransUnion LLCP.O. Box 2000Chester, PA 19016

Online CreditReport FraudAlert Form

https://www.alerts.equifax.com/AutoFraud_Online/jsp/fraudAlert.jsp fraud/center.html

https://www.experian.com/fraud/center.html

https://fraud.transunion.com/fa/fraudAlert/landingPage.jsp

Place a Security Freeze on Your Account. In addition to a fraud alert, you may also have asecurity freeze placed on your credit file. A security freeze will block a credit bureau fromreleasing information from your credit report without your prior written authorization. Please beaware that a security freeze may delay, interfere with, or prevent the timely approval of anyrequests you make for new loans, mortgages, employment, housing or other services. The feesfor placing a security freeze vary by state, and a consumer reporting agency may charge a fee ofup to $10.00 to place a freeze or lift or remove a freeze. To place a security freeze on your creditreport, you may send a written request to each of the major consumer reporting agencies byregular, certified, or overnight mail. You can also place security freezes online by visiting eachconsumer reporting agency online.

Credit Freezes (for Massachusetts Residents): Massachusetts law gives you the right to placea security freeze on your consumer reports. A security freeze is designed to prevent credit, loansand services from being approved in your name without your consent. Using a security freeze,however, may delay your ability to obtain credit. You may request that a freeze be placed onyour credit report by sending a request to a credit reporting agency by certified mail, overnightmail or regular stamped mail to the address below:

Page 13: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

Unlike a fraud alert, you must separately place a credit freeze on your credit file at each creditreporting company. The following information should be included when requesting a securityfreeze (documentation for you and your spouse must be submitted when freezing a spouse’scredit report): full name, with middle initial and any suffixes; Social Security number; date ofbirth (month, day and year); current address and previous addresses for the past five (5) years;and applicable fee (if any) or incident report or complaint with a law enforcement agency or theDepartment of Motor Vehicles. The request should also include a copy of a government-issuedidentification card, such as a driver’s license, state or military ID card, and a copy of a utility bill,bank or insurance statement. Each copy should be legible, display your name and current mailingaddress, and the date of issue (statement dates must be recent). The credit reporting companymay charge a reasonable fee of up to $5 to place a freeze or lift or remove a freeze, unless youare a victim of identity theft or the spouse of a victim of identity theft, and have submitted a validpolice report relating to the identity theft to the credit reporting company.

Equifax Experian TransUnionAddress Equifax Security Freeze

P.O. Box 105788Atlanta, Georgia 30348

Experian Security FreezeP.O. Box 9554Allen, TX 75013

TransUnion LLCP.O. Box 2000Chester, PA 19016

OnlineSecurity FreezeForm

https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo.jsp

https://www.experian.com/freeze/center.html

https://freeze.transunion.com/sf/securityFreeze/landingPage.jsp

Contact Law Enforcement.

If you believe you are the victim of identity theft, you should immediately contact your local lawenforcement agency, your state’s attorney general, or the Federal Trade Commission.

Federal Trade Commission. If your personal information has been misused, visit the FTC’s siteat IdentityTheft.gov to get recovery steps and to file an identity theft complaint. You can alsocall 1-877-ID-THEFT (877-438-4338) or write to Federal Trade Commission at 600Pennsylvania Avenue, NW, Washington, DC 20580 for additional guidance. Your complaint willbe added to the FTC’s Consumer Sentinel Network, where it will be accessible to lawenforcement for their investigations.

State-Specific Information.

For residents of Maryland, North Carolina, and Rhode Island: For information on how toavoid identity theft or to contact your state’s attorney general, please use the below information.

For residents of Massachusetts and Rhode Island: Under Massachusetts and Rhode Islandlaws, you have the right to obtain a police report filed in regard to this incident. If you are thevictim of identity theft, you also have the right to file a police report and obtain a copy of it.

Maryland AttorneyGeneral

North CarolinaAttorney General

Rhoda IslandAttorney General

MassachusettsAttorney General

Phone 1-410-576-6491 1-877-566-7226(within North Carolina)

1-401-274-4400 1-617-727-8400

Page 14: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

or 1-919-716-6000(if outside NorthCarolina)

Email [email protected]

[email protected] [email protected] [email protected]

Address Identity Theft UnitAttorney General ofMaryland200 St. Paul Place,16th FloorBaltimore, MD21202

Consumer ProtectionDivision AttorneyGeneral’s OfficeMail Service Center9001Raleigh, NC 27699-9001

Rhode Island Office ofthe Attorney General150 South Main StreetProvidence, RI 02903

Massachusetts AGOOne Ashburton PlaceBoston, MA 02108-1518

Website https://www.oag.state.md.us/

http://www.ncdoj.gov http:// www.riag.ri.gov http://www.mass.gov/ago/

Page 15: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

Important notification regarding data breach

Dear [Customer],

New England Biolabs® (NEB®) was recently made aware of a data security incident reported byone of our vendors, who handles web order transactions on www.neb.com. Although we areunaware of any actual misuse of your information, we are providing notice to you and otherpotentially affected customers about the incident, as well as providing information regardingtools that you can use to protect yourself against possible identity theft or fraud.

What happened?

We were informed on February 13th, 2017 that the e-commerce portion of ourwebsite, www.neb.com, experienced an intrusion. Our site is operated for us by a third-party"platform provider", and it was the platform provider's systems that experienced the intrusion.The intruder or intruders placed malware on the platform provider's servers, and, by doing so,gained access to our customers' information, including payment card data, where it existed. Todate, the investigation indicates that the intrusion began in February 2016 and ended inDecember 2016. The attackers gained access to customer information, including payment cardnumbers, if used, as customers made transactions on the platform provider's systems. Theattackers additionally had access to historical customer and payment card data, again, where itexisted.

Unfortunately, the platform provider did not discover the breach until November 2016. Whenthey then contacted law enforcement about the breach, law enforcement officials asked thatnotification to customers be delayed to allow the investigation to move forward.

As you have provided your data and payment information to us in the past, we are now notifyingyou about this data breach.

What information was involved?

The information that the attacker had access to includes your first and last name, your address,your phone number, and any debit or credit card numbers with expiration dates that you mayhave used on our website.

What action is being taken?

Our platform provider has worked with a leading cybersecurity firm to remove the malware fromits systems and is now actively monitoring the platform to safeguard personal information. Ourplatform provider has also contacted and offered its cooperation to federal law enforcement.

What You Can Do.

To protect yourself from the possibility of identity theft, if you used a credit or debit card onwww.neb.com, we recommend you immediately contact your card company and inform themthat your card information may have been compromised, so that they can issue you a

Page 16: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

replacement card. Review your banking and card statements and report any suspicious activityto the relevant financial institutions.

For more information on identity theft, we suggest that you visit the website of the CaliforniaOffice of Privacy Protection at www.privacy.ca.gov.

Please be assured that NEB takes matters of data security very seriously. We will continue towork with this platform provider in the ensuing weeks to ensure our online ordering systemremains well protected.

We apologize for this inconvenience and thank you for the continued trust you place in NEB. Ifyou have any questions regarding this incident, please contact me at [email protected].

Sharon KaiserCIO, Director Information Technology

New England Biolabs, Inc.

Page 17: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

K>Z_Q^` Aa`^Qd =McMUU(?C<L

1&$0'2

K588D9EEL

8QM^ KA5@9L&

Aa`^Qd =McMUU ^QOQZ`Xe NQOMYQ McM^Q [R M \[`QZ`UMX _QOa^U`e UZOUPQZ` \[__UNXe MRRQO`UZS `TQ \Q^_[ZMX UZR[^YM`U[Z [R OQ^`MUZ

UZPUbUPaMX_ cT[ YMPQ M \MeYQZ` OM^P \a^OTM_Q [Z `TQ Aa`^Qd'=McMUU(O[Y cQN_U`Q( HQ M^Q \^[bUPUZS `TU_ Z[`UOQ M_ M

\^QOMa`U[Z `[ UZR[^Y \[`QZ`UMXXe MRRQO`QP UZPUbUPaMX_ MN[a` `TQ UZOUPQZ` MZP `[ OMXX e[a^ M``QZ`U[Z `[ _[YQ _`Q\_ e[a OMZ

`MWQ `[ TQX\ \^[`QO` e[a^_QXR( HQ _UZOQ^QXe ^QS^Q` MZe O[ZOQ^Z `TU_ YMe OMa_Q e[a(

*1,; ',77.5.-

HQ cQ^Q ^QOQZ`Xe UZR[^YQP Ne `TQ O[Y\MZe `TM` T[_`_ MZP [\Q^M`Q_ [a^ cQN_U`Q [R M \[`QZ`UMX _QOa^U`e UZOUPQZ` UZb[XbUZS

[a^ cQN_U`Q( 6M_QP a\[Z K?< M<E;FIVJ R[^QZ_UO UZbQ_`USM`U[Z& U` M\\QM^_ `TM` MZ aZMa`T[^UfQP UZPUbUPaMX cM_ MNXQ `[ SMUZ

MOOQ__ `[ \[^`U[Z_ [R [a^ cQN_U`Q MZP UZ_`MXX YMXUOU[a_ _[R`cM^Q [Z `TQ cQN_U`Q _Q^bQ^_ `TM` cM_ PQ_USZQP `[ OM\`a^Q

\MeYQZ` OM^P UZR[^YM`U[Z(

*1,; (5/684,;265 *,9 (5=63=.-

HQ NQXUQbQ `TM` `TQ UZOUPQZ` O[aXP TMbQ MRRQO`QP OQ^`MUZ UZR[^YM`U[Z $UZOXaPUZS ZMYQ& MPP^Q__& QYMUX MPP^Q__& `QXQ\T[ZQ

ZaYNQ^& \MeYQZ` OM^P MOO[aZ` ZaYNQ^& MZP Qd\U^M`U[Z PM`Q% [R UZPUbUPaMX_ cT[ YMPQ M \a^OTM_Q [Z `TQ cQN_U`Q(

5OO[^PUZS `[ [a^ ^QO[^P_& e[a YMPQ M \MeYQZ` OM^P `^MZ_MO`U[Z [Z `TQ cQN_U`Q _[ @KVJ GFJJ@8C< K?7K e[a^ UZR[^YM`U[Z YMe

NQ MRRQO`QP( CXQM_Q Z[`Q `TM` NQOMa_Q cQ P[ Z[` O[XXQO` _QZ_U`UbQ \Q^_[ZMX UZR[^YM`U[Z XUWQ E[OUMX EQOa^U`e ZaYNQ^_& `TU_

`e\Q [R _QZ_U`UbQ UZR[^YM`U[Z cM_ Z[` MRRQO`QP Ne `TU_ UZOUPQZ`(

*1,; *. #8. %6250

HQ `MWQ `TQ \^UbMOe [R \Q^_[ZMX UZR[^YM`U[Z _Q^U[a_Xe& MZP PQQ\Xe ^QS^Q` `TM` `TU_ UZOUPQZ` [OOa^^QP( 4<VM< K7B<E JK<GJ KF

MPP^Q__ `TU_ UZOUPQZ` \^[Y\`Xe MR`Q^ cQ cQ^Q MXQ^`QP `[ U`& UZOXaPUZS O[YYaZUOM`UZS cU`T `TQ bQZP[^ `TM` T[_`_ MZP

[\Q^M`Q_ `TQ cQN_U`Q `[ XQM^Z Y[^Q MN[a` cTM` [OOa^^QP( FTQ bQZP[^ UZR[^YQP a_ `TM` `TQe TMbQ QZSMSQP MZ [a`_UPQ

R[^QZ_UO UZbQ_`USM`U[Z RU^Y `[ M__U_` `TQY UZ UZbQ_`USM`UZS MZP `TM` `TQ bQZP[^ MZP R[^QZ_UO RU^Y M^Q ^QYQPUM`UZS `TQ

_U`aM`U[Z Ne ^QY[bUZS `TQ YMXcM^Q& MZP PQ\X[eUZS RUXQ Y[ZU`[^UZS _[R`cM^Q MZP MZ QZP\[UZ` _QOa^U`e \^[S^MY `[ QZTMZOQ

`TQ _QOa^U`e [R MXX `TQ cQN_U`Q_ `TM` `TQe T[_` MZP [\Q^M`Q( HTUXQ N[`T cQ MZP `TQ bQZP[^ M^Q O[Z`UZaUZS `[ ^QbUQc MZP

QZTMZOQ _QOa^U`e YQM_a^Q_& `TQ UZOUPQZ` TM_ Z[c NQQZ O[Z`MUZQP( >Z MPPU`U[Z& `TQ UZOUPQZ` TM_ NQQZ ^Q\[^`QP `[ RQPQ^MX

XMc QZR[^OQYQZ` MZP `TQ bQZP[^ U_ O[[\Q^M`UZS cU`T `TQU^ UZbQ_`USM`U[Z(

*1,; +6< $,5 %6

HQ ^QO[YYQZP `TM` e[a ^QbUQc O^QPU` MZP PQNU` OM^P MOO[aZ` _`M`QYQZ`_ M_ _[[Z M_ \[__UNXQ UZ [^PQ^ `[ PQ`Q^YUZQ UR `TQ^Q

M^Q MZe PU_O^Q\MZOUQ_ [^ aZa_aMX MO`UbU`e XU_`QP( HQ a^SQ e[a `[ ^QYMUZ bUSUXMZ` MZP O[Z`UZaQ `[ Y[ZU`[^ _`M`QYQZ`_ R[^

aZa_aMX MO`UbU`e S[UZS R[^cM^P( >R e[a _QQ MZe`TUZS e[a P[ Z[` ^QO[SZUfQ& e[a _T[aXP UYYQPUM`QXe Z[`URe `TQ U__aQ^ [R `TQ

O^QPU` [^ PQNU` OM^P M_ cQXX M_ `TQ \^[\Q^ XMc QZR[^OQYQZ` Ma`T[^U`UQ_& UZOXaPUZS X[OMX XMc <E=FI9<D<EKS PFLI JK7K<VJ

7KKFIE<P ><E<I7CS 7E;YFI K?< '<;<I7C 2I7;< $FDD@JJ@FE [W'2$X\U >Z UZ_`MZOQ_ [R \MeYQZ` OM^P R^MaP& U` U_ UY\[^`MZ` `[ Z[`Q

`TM` OM^PT[XPQ^_ M^Q `e\UOMXXe Z[` ^Q_\[Z_UNXQ R[^ MZe R^MaPaXQZ` MO`UbU`e `TM` U_ ^Q\[^`QP UZ M `UYQXe RM_TU[Z(

5X`T[aST E[OUMX _QOa^U`e ZaYNQ^_ cQ^Q Z[` M` ^U_W UZ `TU_ UZOUPQZ`& cQ ^QO[YYQZP& M_ M SQZQ^MX \^MO`UOQ& `TM` e[a OM^QRaXXe

OTQOW e[a^ O^QPU` ^Q\[^`_ R[^ MOO[aZ`_ e[a PUP Z[` [\QZ [^ R[^ UZ]aU^UQ_ R^[Y O^QPU`[^_ e[a PUP Z[` UZU`UM`Q( >R e[a _QQ

MZe`TUZS e[a P[ Z[` aZPQ^_`MZP& OMXX `TQ O^QPU` MSQZOe UYYQPUM`QXe( 5_ MZ MPPU`U[ZMX \^QOMa`U[Z& cQ M^Q \^[bUPUZS

@E=FID7K@FE 7E; I<JFLI9<J KF ?<CG @E;@M@;L7CJ GIFK<9K K?<@I @;<EK@K@<JU 2?@J @E9CL;<J 7E W*E=FID7K@FE "8FLK *;<EK@KP 2?<=K

/IFK<9K@FEX I<=<I<E9< >aUPQ& QZOX[_QP TQ^Q& cTUOT PQ_O^UNQ_ MPPU`U[ZMX _`Q\_ e[a YMe `MWQ `[ TQX\ \^[`QO` e[a^_QXR&

UZOXaPUZS ^QO[YYQZPM`U[Z_ R^[Y `TQ ;QPQ^MX F^MPQ 7[YYU__U[Z ^QSM^PUZS UPQZ`U`e `TQR` \^[`QO`U[Z(

Page 18: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

&68 )68. (5/684,;265

;[^ Y[^Q UZR[^YM`U[Z MN[a` `TU_ UZOUPQZ`& [^ UR e[a TMbQ MPPU`U[ZMX ]aQ_`U[Z_ [^ O[ZOQ^Z_ MN[a` `TU_ UZOUPQZ`& e[a YMe

O[Z`MO` a_ `[XX R^QQ M` 2..'1.3'/+*/ NQ`cQQZ 3MY MZP 3\Y 9M_`Q^Z FUYQ& @[ZPMe `T^[aST ;^UPMe( 5SMUZ& cQ _UZOQ^QXe

^QS^Q` MZe O[ZOQ^Z `TU_ QbQZ` YMe OMa_Q e[a(

EUZOQ^QXe&

K>Z_Q^` <Q^^e7(?C<L

<Q^MXP D( 7e_Qc_WU& CT(8(

C^Q_UPQZ` MZP 79B

Page 19: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

*?8@B>3D<@? 34@ED *67?D<DH 0;78D -B@D75D<@?

.7F<7G $55@E?DC 3?6 %B76<D .7A@BDC# J[a _T[aXP ^QSaXM^Xe ^QbUQc _`M`QYQZ`_ R^[Y e[a^ MOO[aZ`_ MZP \Q^U[PUOMXXe [N`MUZ e[a^ O^QPU`

^Q\[^` R^[Y [ZQ [^ Y[^Q [R `TQ ZM`U[ZMX O^QPU` ^Q\[^`UZS O[Y\MZUQ_( J[a YMe [N`MUZ M R^QQ O[\e [R e[a^ O^QPU` ^Q\[^` [ZXUZQ M`

ccc(MZZaMXO^QPU`^Q\[^`(O[Y& Ne OMXXUZS `[XX'R^QQ +'211'-,,'2,,2& [^ Ne YMUXUZS MZ 5ZZaMX 7^QPU` DQ\[^` DQ]aQ_` ;[^Y $MbMUXMNXQ M`

ccc(MZZaMXO^QPU`^Q\[^`(O[Y% `[4 5ZZaMX 7^QPU` DQ\[^` DQ]aQ_` EQ^bUOQ& C(B( 6[d +*/,2+& 5`XMZ`M& <5& -*-.2'/,2+( J[a YMe MX_[

\a^OTM_Q M O[\e [R e[a^ O^QPU` ^Q\[^` Ne O[Z`MO`UZS [ZQ [^ Y[^Q [R `TQ `T^QQ ZM`U[ZMX O^QPU` ^Q\[^`UZS MSQZOUQ_ XU_`QP M` `TQ N[``[Y [R

`TU_ \MSQ(

J[a _T[aXP MX_[ ^QYMUZ bUSUXMZ` cU`T ^Q_\QO` `[ ^QbUQcUZS e[a^ MOO[aZ` _`M`QYQZ`_ MZP O^QPU` ^Q\[^`_& MZP e[a _T[aXP \^[Y\`Xe ^Q\[^`

MZe _a_\UOU[a_ MO`UbU`e [^ _a_\QO`QP UPQZ`U`e `TQR` `[ `TQ \^[\Q^ XMc QZR[^OQYQZ` Ma`T[^U`UQ_& UZOXaPUZS X[OMX XMc QZR[^OQYQZ`& e[a^

JK7K<VJ 7KKFIE<P ><E<I7CS 7E;YFI K?< '<;<I7C 2I7;< $FDD@JJ@FE [W'2$X\U 6FL D7P 9FEK79K K?< '2$ FI PFLI JK7K<VJ I<>LC7KFIP 7L`T[^U`e `[

[N`MUZ MPPU`U[ZMX UZR[^YM`U[Z MN[a` Mb[UPUZS MZP \^[`QO`U[Z MSMUZ_` UPQZ`U`e `TQR`4 ;QPQ^MX F^MPQ 7[YYU__U[Z& 7[Z_aYQ^ DQ_\[Z_Q

7QZ`Q^ 0** CQZZ_eXbMZUM 5bQZaQ& AH& HM_TUZS`[Z& 87 ,*/2*& +'211'>8F=9;F $.-2'.--2%& ccc(R`O(S[b)UP`TQR`(

(@B B7C<67?DC @8 +3BH=3?64 J[a YMe MX_[ [N`MUZ UZR[^YM`U[Z MN[a` \^QbQZ`UZS MZP Mb[UPUZS UPQZ`U`e `TQR` R^[Y `TQ @M^eXMZP

BRRUOQ [R `TQ 5``[^ZQe <QZQ^MX4 @M^eXMZP BRRUOQ [R `TQ 5``[^ZQe <QZQ^MX& 7[Z_aYQ^ C^[`QO`U[Z 8UbU_U[Z& ,** E`( CMaX CXMOQ&

6MX`UY[^Q& @8 ,+,*,& +'222'1.-'**,-& ccc([MS(_`M`Q(YP(a_

(@B B7C<67?DC @8 ,@BD; %3B@=<?34 J[a YMe MX_[ [N`MUZ UZR[^YM`U[Z MN[a` \^QbQZ`UZS MZP Mb[UPUZS UPQZ`U`e `TQR` R^[Y A[^`T

$7IFC@E7 "KKFIE<P (<E<I7CVJ .==@9<T -FIK? $7IFC@E7 "KKFIE<P (<E<I7CVJ BRRUOQ& 7[Z_aYQ^ C^[`QO`U[Z 8UbU_U[Z& 3**+ @MUX EQ^bUOQ

7QZ`Q^& DMXQUST& A7 ,1033'3**+& +'211'/'AB'E75@& ccc(ZOP[V(S[b(

(@B B7C<67?DC @8 .;@67 *C=3?6 J[a YMe MX_[ [N`MUZ UZR[^YM`U[Z MN[a` \^QbQZ`UZS MZP Mb[UPUZS UPQZ`U`e `TQR` R^[Y `TQ DT[PQ

>_XMZP BRRUOQ [R `TQ 5``[^ZQe <QZQ^MX4 DT[PQ >_XMZP BRRUOQ [R `TQ 5``[^ZQe <QZQ^MX& 7[Z_aYQ^ C^[`QO`U[Z GZU`& +/* E[a`T @MUZ

E`^QQ`& C^[bUPQZOQ& D> *,3*-& .*+',1.'..**& T``\4))ccc(^UMS(^U(S[b(

(B3E6 $=7BDC# FTQ^Q M^Q MX_[ `c[ `e\Q_ [R R^MaP MXQ^`_ `TM` e[a OMZ \XMOQ [Z e[a^ O^QPU` ^Q\[^` `[ \a` e[a^ O^QPU`[^_ [Z Z[`UOQ `TM` e[a

YMe NQ M bUO`UY [R R^MaP4 MZ UZU`UMX MXQ^` MZP MZ Qd`QZPQP MXQ^`( J[a YMe M_W `TM` MZ UZU`UMX R^MaP MXQ^` NQ \XMOQP [Z e[a^ O^QPU` ^Q\[^` UR

e[a _a_\QO` e[a TMbQ NQQZ& [^ M^Q MN[a` `[ NQ& M bUO`UY [R UPQZ`U`e `TQR`( 5Z UZU`UMX R^MaP MXQ^` _`Me_ [Z e[a^ O^QPU` ^Q\[^` R[^ M` XQM_` 3*

PMe_( J[a YMe TMbQ MZ Qd`QZPQP MXQ^` \XMOQP [Z e[a^ O^QPU` ^Q\[^` UR e[a TMbQ MX^QMPe NQQZ M bUO`UY [R UPQZ`U`e `TQR` cU`T `TQ

M\\^[\^UM`Q P[OaYQZ`M^e \^[[R( 5Z Qd`QZPQP R^MaP MXQ^` _`Me_ [Z e[a^ O^QPU` ^Q\[^` R[^ _QbQZ eQM^_( J[a OMZ \XMOQ M R^MaP MXQ^` [Z e[a^

O^QPU` ^Q\[^` Ne O[Z`MO`UZS MZe [R `TQ `T^QQ ZM`U[ZMX O^QPU` ^Q\[^`UZS MSQZOUQ_ M` `TQ MPP^Q__Q_ [^ `[XX'R^QQ ZaYNQ^_ XU_`QP M` `TQ N[``[Y

[R `TU_ \MSQ(

%B76<D (B77I7C# J[a YMe TMbQ `TQ ^UST` `[ \a` M O^QPU` R^QQfQ& MX_[ WZ[cZ M_ M _QOa^U`e R^QQfQ& [Z e[a^ O^QPU` RUXQ& _[ `TM` Z[ ZQc O^QPU`

OMZ NQ [\QZQP UZ e[a^ ZMYQ cU`T[a` `TQ a_Q [R M C>A ZaYNQ^ `TM` U_ U__aQP `[ e[a cTQZ e[a UZU`UM`Q M R^QQfQ( 5 O^QPU` R^QQfQ U_ PQ_USZQP

`[ \^QbQZ` \[`QZ`UMX O^QPU` S^MZ`[^_ R^[Y MOOQ__UZS e[a^ O^QPU` ^Q\[^` cU`T[a` e[a^ O[Z_QZ`( >R e[a \XMOQ M O^QPU` R^QQfQ& \[`QZ`UMX

O^QPU`[^_ MZP [`TQ^ `TU^P \M^`UQ_ cUXX Z[` NQ MNXQ `[ SQ` MOOQ__ `[ e[a^ O^QPU` ^Q\[^` aZXQ__ e[a `QY\[^M^UXe XUR` `TQ R^QQfQ( FTQ^QR[^Q&

a_UZS M O^QPU` R^QQfQ YMe PQXMe e[a^ MNUXU`e `[ [N`MUZ O^QPU`( >Z MPPU`U[Z& e[a YMe UZOa^ RQQ_ `[ \XMOQ& XUR` MZP)[^ ^QY[bQ M O^QPU` R^QQfQ(

7^QPU` R^QQfQ XMc_ bM^e R^[Y _`M`Q `[ _`M`Q( FTQ O[_` [R \XMOUZS& `QY\[^M^UXe XUR`UZS& MZP ^QY[bUZS M O^QPU` R^QQfQ MX_[ bM^UQ_ Ne _`M`Q&

SQZQ^MXXe #/ `[ #,* \Q^ MO`U[Z M` QMOT O^QPU` ^Q\[^`UZS O[Y\MZe( GZXUWQ M R^MaP MXQ^`& e[a Ya_` _Q\M^M`QXe \XMOQ M O^QPU` R^QQfQ [Z e[a^

O^QPU` RUXQ M` QMOT O^QPU` ^Q\[^`UZS O[Y\MZe( EUZOQ `TQ UZ_`^aO`U[Z_ R[^ T[c `[ Q_`MNXU_T M O^QPU` R^QQfQ PURRQ^ R^[Y _`M`Q `[ _`M`Q& \XQM_Q

O[Z`MO` `TQ `T^QQ YMV[^ O^QPU` ^Q\[^`UZS O[Y\MZUQ_ M_ _\QOURUQP NQX[c `[ RUZP [a` Y[^Q UZR[^YM`U[Z(

J[a OMZ [N`MUZ Y[^Q UZR[^YM`U[Z MN[a` R^MaP MXQ^`_ MZP O^QPU` R^QQfQ_ Ne O[Z`MO`UZS `TQ ;F7 [^ [ZQ [R `TQ ZM`U[ZMX O^QPU` ^Q\[^`UZS

MSQZOUQ_ XU_`QP NQX[c(

,3D<@?3= %B76<D .7A@BD<?9 $97?5<7C %@?D35D *?8@B>3D<@?

9]aURMd $ccc(Q]aURMd(O[Y%

)7?7B3= %@?D35D#

C(B( 6[d 1.*,.+

5`XMZ`M& <5 -*-1.

2**'02/'++++

(B3E6 $=7BDC4

C(B( 6[d 1.*,/0& 5`XMZ`M& <5 -*-1.

%B76<D (B77I7C4

C(B( 6[d +*/122& 5`XMZ`M& <5 -*-.2

9d\Q^UMZ $ccc(Qd\Q^UMZ(O[Y%

)7?7B3= %@?D35D#

C(B( 6[d ,**,

5XXQZ& FI 1/*+-

222'-31'-1.,

(B3E6 $=7BDC 3?6 /75EB<DH (B77I7C#

C(B( 6[d 3//.& 5XXQZ& FI 1/*+-

F^MZ_GZU[Z $ccc(`^MZ_aZU[Z(O[Y%

)7?7B3= %@?D35D#

C(B( 6[d +*/,2+

5`XMZ`M& <5 -*-.2

211'-,,'2,,2

(B3E6 $=7BDC 3?6 /75EB<DH (B77I7C#

C(B( 6[d ,***& 7TQ_`Q^& C5 +3*,,

222'3*3'221,

Page 20: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

@6LPEOQ DBQEA

@8BKEA

@2DDOEPPA

@3IQSA& @=QBQEA @?6;A

=VRc @8BKEA*

MV RcV hcZeZ_X e` _`eZWj j`f `W R_ Z_TZUV_e eYRe Z_g`]gVd TVceRZ_ `W j`fc aVcd`_R] Z_W`c^ReZ`_, KYVeYZcU+aRcej T`^aR_j T`_ecRTeVU e` `aVcReV `fc V+T`^^VcTV a]ReW`c^* 9ae`d* B_T, (n9ae`do)* hYZTY R]d`dfaa`ced `fc ScR_Ud MZ_U ' MVReYVc* AVRceYJ`_X* ERXZT <RSZ_* R_U Hc`S]V^ J`]gVcd* R_U W`c^Vc]jdfaa`ceVU `fc dfSdZUZRcjmd ScR_U IVfdVZe* Z_W`c^VU fd `_ ?VScfRcj 4* 0./5* eYRe Ze YRU ViaVcZV_TVU R^R]hRcV Z_ecfdZ`_ `W Zed djdeV^d ]Rde jVRc, K` UReV* eYV Z_gVdeZXReZ`_ Z_UZTReVd eYRe eYV Z_ecfdZ`_ `_9ae`dm djdeV^d `TTfccVU SVehVV_ ?VScfRcj 0./4 R_U =VTV^SVc 0./4* R_U Z_T]fUVU RTTVdd e` TVceRZ_`W `fc Tfde`^Vcdm aVcd`_R] Z_W`c^ReZ`_ W`c ecR_dRTeZ`_d UfcZ_X eYRe eZ^V aVcZ`U* Rd hV]] Rd ecR_dRTeZ`_dUReZ_X SRT\ e` 0./1, KYV aVcd`_R] Z_W`c^ReZ`_ Z_g`]gVU Z_ eYV Z_TZUV_e ^Rj YRgV Z_T]fUVU j`fc _R^V*RUUcVdd* aY`_V _f^SVc R_U aRj^V_e TRcU Z_W`c^ReZ`_ (Z_T]fUZ_X ViaZcReZ`_ UReVd R_U* Z_ ]Z^ZeVU TRdVd*dVTfcZej T`UVd), Gfc cVT`cUd Z_UZTReV eYRe j`fc TcVUZe TRcU(d) V_UZ_X Z_ PiiiiQ hRd Z^aRTeVU,

MV YRgV SVV_ Z_W`c^VU eYRe 9ae`d Zd h`c\Z_X hZeY R ]VRUZ_X TjSVcdVTfcZej WZc^ R_U YRd eR\V_ deVad e`dVTfcV djdeV^d R_U UVeVc^Z_V eYV _RefcV `W eYV Z_TZUV_e, 9ae`d Zd R]d` h`c\Z_X hZeY ]Rh V_W`cTV^V_eRfeY`cZeZVd Z_ eYVZc Z_gVdeZXReZ`_, KYV TcVUZe TRcU T`^aR_ZVd R_U ZddfZ_X SR_\d RcV SVZ_X T`_eRTeVU W`ceYV afca`dVd `W ZUV_eZWjZ_X f_RfeY`cZkVU TYRcXVd,

;RdVU `_ eYV Z_W`c^ReZ`_ hV YRgV Re eYZd eZ^V* eYVcV Zd _` VgZUV_TV eYRe R_j `W eYV Z_W`c^ReZ`_ YRdSVV_ ^ZdfdVU Rd R cVdf]e `W eYZd Z_TZUV_e, MV cVXcVe eYRe eYZd Z_TZUV_e ^Rj RWWVTe j`f, MV eR\V `fc`S]ZXReZ`_ e` dRWVXfRcU aVcd`_R] Z_W`c^ReZ`_ gVcj dVcZ`fd]j R_U RcV R]VceZ_X j`f RS`fe eYZd Z_TZUV_e d`j`f TR_ eR\V deVad e` YV]a ac`eVTe j`fcdV]W, O`f RcV V_eZe]VU f_UVc L,J, ]Rh e` `_V WcVV TcVUZe cVa`ceR__fR]]j Wc`^ VRTY `W eYV eYcVV _ReZ`_hZUV T`_df^Vc cVa`ceZ_X RXV_TZVd, K` `cUVc j`fc WcVV TcVUZecVa`ce* gZdZe hhh,R__fR]TcVUZecVa`ce,T`^ `c TR]] e`]]+WcVV Re /+655+100+6006,

MV V_T`fcRXV j`f e` cV^RZ_ gZXZ]R_e Sj cVgZVhZ_X j`fc RTT`f_e deReV^V_ed R_U ^`_Ze`cZ_X j`fc WcVVTcVUZe cVa`ced, ?fceYVc^`cV* eYV ReeRTYVU IVWVcV_TV @fZUV ac`gZUVd cVT`^^V_UReZ`_d Sj eYV L,J,?VUVcR] KcRUV <`^^ZddZ`_ `_ eYV ac`eVTeZ`_ `W aVcd`_R] Z_W`c^ReZ`_,

MV Y`aV eYZd Z_W`c^ReZ`_ Zd fdVWf] e` j`f, BW j`f YRgV R_j bfVdeZ`_d cVXRcUZ_X eYZd Z_TZUV_e* a]VRdVTR]] *'/))',),')-.+& 7MLDBS QHOMRGH 4OIDBS 01))BK QM .1))NK& EBPQEOL PQBLDBOD QIKE(

9XRZ_* hV cVXcVe R_j Z_T`_gV_ZV_TV eYZd ^Rj TRfdV j`f,

JZ_TVcV]j*

=R_R HRaaRd* <?G

Page 21: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

<EFEOELCE 5RIDE

MV V_T`fcRXV `fc RWWVTeVU Tfde`^Vcd e` eR\V eYV W`]]`hZ_X deVad8

9ODEO >MRO 4OEE 3OEDIQ <ENMOQ( K` `cUVc j`fc WcVV TcVUZe cVa`ce* gZdZe hhh,R__fR]TcVUZecVa`ce,T`^* TR]]e`]]+WcVV Re /+655+100+6006* `c T`^a]VeV eYV 9__fR] <cVUZe IVa`ce IVbfVde ?`c^ `_ eYV L,J, ?VUVcR] KcRUV<`^^ZddZ`_md (n?K<o) hVSdZeV Re hhh,T`_df^Vc,WeT,X`g R_U ^RZ] Ze e` 9__fR] <cVUZe IVa`ce IVbfVdeJVcgZTV* H,G, ;`i /.306/* 9e]R_eR* @9 1.126+306/, KYV eYcVV T`_df^Vc cVa`ceZ_X RXV_TZVd ac`gZUV WcVVR__fR] TcVUZe cVa`ced `_]j eYc`fXY eYV hVSdZeV* e`]]+WcVV _f^SVc `c cVbfVde W`c^,

MYV_ j`f cVTVZgV j`fc TcVUZe cVa`ce* cVgZVh Ze TRcVWf]]j, D``\ W`c RTT`f_ed j`f UZU _`e `aV_, D``\ Z_ eYVnZ_bfZcZVdo dVTeZ`_ W`c _R^Vd `W TcVUZe`cd Wc`^ hY`^ j`f YRgV_me cVbfVdeVU TcVUZe, J`^V T`^aR_ZVd SZ]]f_UVc _R^Vd `eYVc eYR_ eYVZc de`cV `c T`^^VcTZR] _R^Vd, KYV T`_df^Vc cVa`ceZ_X RXV_Tj hZ]] SV RS]V e`eV]] j`f hYV_ eYRe Zd eYV TRdV, D``\ Z_ eYV naVcd`_R] Z_W`c^ReZ`_o dVTeZ`_ W`c R_j Z_RTTfcRTZVd Z_ j`fcZ_W`c^ReZ`_ (dfTY Rd Y`^V RUUcVdd R_U J`TZR] JVTfcZej _f^SVc), BW j`f dVV R_jeYZ_X j`f U` _`ef_UVcdeR_U* TR]] eYV T`_df^Vc cVa`ceZ_X RXV_Tj Re eYV eV]VaY`_V _f^SVc `_ eYV cVa`ce, >cc`cd Z_ eYZdZ_W`c^ReZ`_ ^Rj SV R hRc_Z_X dZX_ `W a`ddZS]V ZUV_eZej eYVWe, O`f dY`f]U _`eZWj eYV T`_df^Vc cVa`ceZ_XRXV_TZVd `W R_j Z_RTTfcRTZVd Z_ j`fc cVa`ce* hYVeYVc UfV e` Vcc`c `c WcRfU* Rd d``_ Rd a`ddZS]V d` eYVZ_W`c^ReZ`_ TR_ SV Z_gVdeZXReVU R_U* ZW W`f_U e` SV Z_ Vcc`c* T`ccVTeVU, BW eYVcV RcV RTT`f_ed `c TYRcXVd j`fUZU _`e RfeY`cZkV* Z^^VUZReV]j _`eZWj eYV Raac`acZReV T`_df^Vc cVa`ceZ_X RXV_Tj Sj eV]VaY`_V R_U Z_hcZeZ_X, <`_df^Vc cVa`ceZ_X RXV_Tj deRWW hZ]] cVgZVh j`fc cVa`ce hZeY j`f, BW eYV Z_W`c^ReZ`_ TR_me SVVia]RZ_VU* eYV_ j`f hZ]] _VVU e` TR]] eYV TcVUZe`cd Z_g`]gVU, B_W`c^ReZ`_ eYRe TR_me SV Via]RZ_VU R]d` dY`f]USV cVa`ceVU e` j`fc ]`TR] a`]ZTV `c dYVcZWWmd `WWZTV Rd Ze ^Rj dZX_R] TcZ^Z_R] RTeZgZej,

<ENMOQ 6LCIDELQP( BW j`f UVeVTe R_j f_RfeY`cZkVU ecR_dRTeZ`_d Z_ R WZ_R_TZR] RTT`f_e* ac`^ae]j _`eZWj j`fcaRj^V_e TRcU T`^aR_j `c WZ_R_TZR] Z_deZefeZ`_, BW j`f UVeVTe R_j Z_TZUV_e `W ZUV_eZej eYVWe `c WcRfU*ac`^ae]j cVa`ce eYV Z_TZUV_e e` ]Rh V_W`cTV^V_e* eYV ?K< R_U j`fc deReV 9ee`c_Vj @V_VcR], BW j`f SV]ZVgVj`fc ZUV_eZej YRd SVV_ de`]V_* eYV ?K< cVT`^^V_Ud eYV W`]]`hZ_X deVad8

" <]`dV eYV RTT`f_ed eYRe j`f YRgV T`_WZc^VU `c SV]ZVgV YRgV SVV_ eR^aVcVU hZeY `c `aV_VUWcRfUf]V_e]j, LdV eYV ?K<md B= KYVWe 9WWZURgZe (RgRZ]RS]V Re hhh,WeT,X`g-ZUeYVWe) hYV_ j`fUZdafeV _Vh f_RfeY`cZkVU RTT`f_ed,

" ?Z]V R ]`TR] a`]ZTV cVa`ce, GSeRZ_ R T`aj `W eYV a`]ZTV cVa`ce R_U dfS^Ze Ze e` j`fc TcVUZe`cd R_UR_j `eYVcd eYRe ^Rj cVbfZcV ac``W `W eYV ZUV_eZej eYVWe TcZ^V,

O`f TR_ T`_eRTe eYV ?K< e` ]VRc_ ^`cV RS`fe Y`h e` ac`eVTe j`fcdV]W Wc`^ SVT`^Z_X R gZTeZ^ `W ZUV_eZejeYVWe R_U Y`h e` cVaRZc ZUV_eZej eYVWe8

?VUVcR] KcRUV <`^^ZddZ`_<`_df^Vc IVda`_dV <V_eVc4.. HV__dj]gR_ZR 9gV_fV*FMMRdYZ_Xe`_* =< 0.36./+655+B=KA>?K (216+2116)hhh,WeT,X`g-ZUeYVWe-

Page 22: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

3MLPIDEO ;JBCILG B 4OBRD 2JEOQ ML >MRO 3OEDIQ 4IJE( K` ac`eVTe j`fcdV]W Wc`^ a`ddZS]V ZUV_eZej eYVWe*T`_dZUVc a]RTZ_X R WcRfU R]Vce `_ j`fc TcVUZe WZ]V, 9 WcRfU R]Vce YV]ad ac`eVTe j`f RXRZ_de eYV a`ddZSZ]Zej `WR_ ZUV_eZej eYZVW `aV_Z_X _Vh TcVUZe RTT`f_ed Z_ j`fc _R^V, MYV_ R ^VcTYR_e TYVT\d eYV TcVUZe YZde`cj `Wd`^V`_V Raa]jZ_X W`c TcVUZe* eYV ^VcTYR_e XVed R _`eZTV eYRe eYV Raa]ZTR_e ^Rj SV eYV gZTeZ^ `W ZUV_eZejeYVWe, KYV R]Vce _`eZWZVd eYV ^VcTYR_e e` eR\V deVad e` gVcZWj eYV ZUV_eZej `W eYV Raa]ZTR_e, O`f TR_ a]RTV RWcRfU R]Vce `_ j`fc TcVUZe cVa`ce Sj TR]]Z_X R_j `_V `W eYV e`]]+WcVV _f^SVcd ac`gZUVU SV]`h, O`f hZ]] cVRTYR_ Rfe`^ReVU eV]VaY`_V djdeV^ eYRe R]]`hd j`f e` W]RX j`fc WZ]V hZeY R WcRfU R]Vce Re R]] eYcVV T`_df^VccVa`ceZ_X RXV_TZVd, ?`c ^`cV Z_W`c^ReZ`_ `_ WcRfU R]Vced* j`f R]d` ^Rj T`_eRTe eYV ?K< Rd UVdTcZSVURS`gV,

>bfZWRi >bfZWRi <cVUZe B_W`c^ReZ`_ JVcgZTVd*

B_T,

H,G, ;`i 52.02/

9e]R_eR* @9 1.152

/+6..+303+4063 hhh,VbfZWRi,T`^

>iaVcZR_ >iaVcZR_ B_T,

H,G, ;`i 7332

9]]V_* KN 53./1

/+666+175+1520 hhh,ViaVcZR_,T`^

KcR_dL_Z`_ KcR_dL_Z`_ DD<

H,G, ;`i 0...

<YVdeVc* H9 /7.00+0...

/+6..+46.+5067 hhh,ecR_df_Z`_,T`^

3MLPIDEO ;JBCILG B =ECROIQS 4OEETE ML >MRO 3OEDIQ 4IJE( O`f ^Rj hZdY e` a]RTV R ndVTfcZej WcVVkVo(R]d` \_`h_ Rd R nTcVUZe WcVVkVo) `_ j`fc TcVUZe WZ]V, 9 dVTfcZej WcVVkV Zd UVdZX_VU e` acVgV_e a`eV_eZR]TcVUZe`cd Wc`^ RTTVddZ_X j`fc TcVUZe WZ]V Re eYV T`_df^Vc cVa`ceZ_X RXV_TZVd hZeY`fe j`fc T`_dV_e, KYVcV^Rj SV WVVd W`c a]RTZ_X* ]ZWeZ_X* R_U-`c cV^`gZ_X R dVTfcZej WcVVkV* hYZTY XV_VcR]]j cR_XV Wc`^ &3+&0. aVcRTeZ`_, '31/0+ ( ,6(9* (1+68& <49 2978 51()+ ( 7+)96/8< ,6++=+ 43 <496 )6+*/8 ,/1+ (8 +(). )43792+6

6+5468/3- (-+3)< /3*/;/*9(11<, ?`c ^`cV Z_W`c^ReZ`_ `_ dVTfcZej WcVVkVd* j`f ^Rj T`_eRTe eYV eYcVV_ReZ`_hZUV T`_df^Vc cVa`ceZ_X RXV_TZVd `c eYV ?K< Rd UVdTcZSVU RS`gV, 9d eYV Z_decfTeZ`_d W`cVdeRS]ZdYZ_X R dVTfcZej WcVVkV UZWWVc Wc`^ deReV e` deReV* a]VRdV T`_eRTe eYV eYcVV _ReZ`_hZUV T`_df^VccVa`ceZ_X RXV_TZVd e` WZ_U `fe ^`cV Z_W`c^ReZ`_, KYV T`_df^Vc cVa`ceZ_X RXV_TZVd ^Rj cVbfZcV ac`aVcZUV_eZWZTReZ`_ acZ`c e` Y`_`cZ_X j`fc cVbfVde, ?`c ViR^a]V* j`f ^Rj SV Rd\VU e` ac`gZUV8

" O`fc Wf]] _R^V hZeY ^ZUU]V Z_ZeZR] R_U XV_VcReZ`_ (dfTY Rd Cc,* Jc,* BB* BBB)

" O`fc J`TZR] JVTfcZej _f^SVc

" O`fc UReV `W SZceY

" 9UUcVddVd hYVcV j`f YRgV ]ZgVU `gVc eYV aRde WZgV jVRcd

" 9 ]VXZS]V T`aj `W R X`gVc_^V_e+ZddfVU ZUV_eZWZTReZ`_ TRcU (dfTY Rd R deReV UcZgVcmd ]ZTV_dV `c^Z]ZeRcj B= TRcU)

" Hc``W `W j`fc TfccV_e cVdZUV_eZR] RUUcVdd (dfTY Rd R TfccV_e feZ]Zej SZ]] `c RTT`f_e deReV^V_e)

4MO 7BOSJBLD <EPIDELQP( O`f TR_ `SeRZ_ Z_W`c^ReZ`_ Wc`^ eYV ERcj]R_U GWWZTV `W eYV 9ee`c_Vj @V_VcR]RS`fe deVad j`f TR_ eR\V e` Rg`ZU ZUV_eZej eYVWe, O`f ^Rj T`_eRTe eYV ERcj]R_U 9ee`c_Vj @V_VcR] Re8

ERcj]R_U GWWZTV `W eYV 9ee`c_Vj @V_VcR]<`_df^Vc Hc`eVTeZ`_ =ZgZdZ`_0.. Je, HRf] H]RTV;R]eZ^`cV* E= 0/0.0(666) 521+..01 (e`]]+WcVV Z_ ERcj]R_U)(2/.) 354+41..hhh,`RX,deReV,^U,fd

Page 23: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

4MO 7BPPBCHRPEQQP <EPIDELQP( O`f YRgV eYV cZXYe e` `SeRZ_ R a`]ZTV cVa`ce R_U cVbfVde R dVTfcZej WcVVkV RdUVdTcZSVU RS`gV, KYV T`_df^Vc cVa`ceZ_X RXV_TZVd ^Rj TYRcXV j`f R WVV `W fa e` &3 e` a]RTV R dVTfcZejWcVVkV `_ j`fc RTT`f_e* R_U ^Rj cVbfZcV eYRe j`f ac`gZUV TVceRZ_ aVcd`_R] Z_W`c^ReZ`_ (dfTY Rd j`fc _R^V*J`TZR] JVTfcZej _f^SVc* UReV `W SZceY* R_U RUUcVdd) R_U ac`aVc ZUV_eZWZTReZ`_ (dfTY Rd R T`aj `W RX`gVc_^V_e+ZddfVU B= TRcU R_U R SZ]] `c deReV^V_e) acZ`c e` Y`_`cZ_X j`fc cVbfVde, KYVcV Zd _` TYRcXV*Y`hVgVc* e` a]RTV* ]ZWe `c cV^`gV R dVTfcZej WcVVkV ZW j`f YRgV SVV_ R gZTeZ^ `W ZUV_eZej eYVWe R_U j`fac`gZUV eYV T`_df^Vc cVa`ceZ_X RXV_TZVd hZeY R gR]ZU a`]ZTV cVa`ce,

4MO 8MOQH 3BOMJILB <EPIDELQP( O`f TR_ `SeRZ_ Z_W`c^ReZ`_ Wc`^ eYV F`ceY <Rc`]Z_R 9ee`c_Vj @V_VcR]mdGWWZTV RS`fe acVgV_eZ_X ZUV_eZej eYVWe, O`f TR_ T`_eRTe eYV F`ceY <Rc`]Z_R 9ee`c_Vj @V_VcR] Re8

F`ceY <Rc`]Z_R 9ee`c_Vj @V_VcR]md GWWZTV7../ ERZ] JVcgZTV <V_eVcIR]VZXY* F< 05477+7../(655) 344+5004 (e`]]+WcVV Z_ F`ceY <Rc`]Z_R)(7/7) 5/4+42..hhh,_TU`[,X`g

4MO 9OEGML <EPIDELQP( MV V_T`fcRXV j`f e` cVa`ce dfdaVTeVU ZUV_eZej eYVWe e` eYV GcVX`_ 9ee`c_Vj

@V_VcR] Re8

GcVX`_ =VaRce^V_e `W CfdeZTV//40 <`fce JecVVe F>JR]V * GI 751./+2.74(655) 655+7170 (e`]]+WcVV Z_ GcVX`_)(3.1) 156+22..Yeea8--hhh,U`[,deReV,`c,fd

4MO <HMDE 6PJBLD <EPIDELQP( O`f ^Rj `SeRZ_ Z_W`c^ReZ`_ RS`fe acVgV_eZ_X R_U Rg`ZUZ_X ZUV_eZej eYVWe

Wc`^ eYV IY`UV Bd]R_U GWWZTV `W eYV 9ee`c_Vj @V_VcR] Re8

IY`UV Bd]R_U GWWZTV `W eYV 9ee`c_Vj @V_VcR]<`_df^Vc Hc`eVTeZ`_ L_Ze/3. J`feY ERZ_ JecVVeHc`gZUV_TV* IB .07.1(2./)+052+22..Yeea8--hhh,cZRX,cZ,X`g

O`f YRgV eYV cZXYe e` `SeRZ_ R a`]ZTV cVa`ce R_U cVbfVde R dVTfcZej WcVVkV Rd UVdTcZSVU RS`gV, KYV T`_df^VccVa`ceZ_X RXV_TZVd ^Rj TYRcXV j`f R WVV `W fa e` &/. e` a]RTV R dVTfcZej WcVVkV `_ j`fc RTT`f_e* R_U ^RjcVbfZcV eYRe j`f ac`gZUV TVceRZ_ aVcd`_R] Z_W`c^ReZ`_ (dfTY Rd j`fc _R^V* J`TZR] JVTfcZej _f^SVc* UReV `WSZceY* R_U RUUcVdd) R_U ac`aVc ZUV_eZWZTReZ`_ (dfTY Rd R T`aj `W R X`gVc_^V_e+ZddfVU B= TRcU R_U R SZ]] `cdeReV^V_e) acZ`c e` Y`_`cZ_X j`fc cVbfVde W`c R dVTfcZej WcVVkV, KYVcV Zd _` TYRcXV* Y`hVgVc* e` a]RTV* ]ZWe `ccV^`gV R dVTfcZej WcVVkV ZW j`f YRgV SVV_ R gZTeZ^ `W ZUV_eZej eYVWe R_U j`f ac`gZUV eYV T`_df^Vc cVa`ceZ_XRXV_TZVd hZeY R gR]ZU a`]ZTV cVa`ce,

Page 24: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

Notice of Data Breach

Dear Customer:

We are writing to you because of an incident involving access to information associated with

online purchases made on our website www.sport-smart.com Although we are unaware of any

actual misuse of information, we are providing notice to you and other potentially affected

customers about the incident.

We were informed on February 6, 2017 that our website experienced an intrusion last year. Our

site is operated for us by a third-party company, Aptos, and it was their systems that

experienced this intrusion. The intruder or intruders placed malware on the platform provider’s

servers, and by doing so gained access to customers’ payment data. To date, the investigation

indicates that the intrusion began in approximately February 2016 and ended in December

2016. The attackers gained access to information including payment card numbers as

customers made transactions on the platform provider’s systems, and had access to historical

payment data. Because you have provided your payment card information to us in the past, we

are notifying you about this data breach.

You may wonder why you are hearing about the breach now. Aptos did not discover the breach

until November. In addition, we were asked that notification to customers be delayed to allow

the investigation to move forward.

The information that the attacker had access to includes name, address, phone number and

debit or credit card numbers with expiration dates you may have used on our website.

Aptos has worked with a leading cybersecurity firm to remove the malware from its systems and

is actively monitoring the platform to safeguard personal information. Aptos has also contacted

and offered its cooperation to federal law enforcement.

Sport-Smart.com has now moved it’s site off the Aptos platform to a more secure platform that

does not store credit card data. This will help to ensure a safer customer shopping experience

for our customers.

To protect yourself for the possibility of your data being misused we recommend that you

contact your credit or debit card company and inform them that your card information may have

been compromised, so that they can issue you a replacement card. Review your banking and

card statements and report any suspicious activity to the relevant financial institutions.

Page 25: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

[First_Name] [Last_Name][Address_Line_1][Address_Line_2][City], [State] [Zip]

[Date]Dear [First_Name] [Last_Name],

We are writing to inform you of an incident that may have involved your personal information. An incidentinvolving unauthorized access to information associated with certain purchases made on ourwebsite vapourbeauty.com. On February 9, 2017, we were notified of the incident by Aptos, the third-party digital platform provider that hosts our ecommerce site. We wanted to share information and informyou that Vapourbeauty.com, Aptos and law enforcement are responding. Although we have not beeninformed of any actual misuse of your information, we wanted to provide you this notice and informationon how you can protect your credit and debit accounts.

You may wonder why you are hearing about the breach now. We understand that Aptos contactedFederal law enforcement agencies and the U.S. Department of Justice at that time. Law enforcementrequested that notification to businesses (including Vapourbeauty.com) and customers be delayed toallow the investigation to move forward.

What Information Was Involved?Aptos has informed us that attackers had access to the following online data associated with orders madebefore «Date»:

" First and last name," Address," Phone number," Email address, and" Debit or credit card number with expiration dates.

What Happened?On February 9, 2017, we were informed that Aptos experienced a security incident last year that involvedour website (Vapourbeauty.com). Aptos has indicated that the intrusion began in February 2016 andended in December 2016. During that time, we understand that cyber criminals placed malware on Aptos’servers and gained access to Vapourbeauty.com’s data. We have been assured that the malware hasbeen removed and that the criminals no longer have access to their systems or data.

We want to make you aware of steps you may take to guard against identity theft or fraud. Please reviewthe enclosed Information about Identity Theft Protection.

[REQUIRED PRODUCT/SERVICE LANGUAGE START]

As an added precaution, we have arranged to have AllClear ID protect your identity for «Time» months at nocost to you. The following identity protection services start on the date of this notice and you can use themat any time during the next «Time» months.

[RETURN MAIL ADDRESS – Inserted By AllClear ID]

Page 26: Notice of Data Breach - Attorney General of California Inc multiple notices... · [Customer name] [Customer address] [City, State, Zip] Notice of Data Breach Dear [Customer name]:

AllClear Identity Repair: This service is automatically available to you with no enrollment required. If aproblem arises, simply call «DID_Phone» and a dedicated investigator will help recover financial losses,restore your credit and make sure your identity is returned to its proper condition.

AllClear Credit Monitoring: This service offers additional layers of protection including credit monitoring anda $1 million identity theft insurance policy. To use this service, you will need to provide your personalinformation to AllClear ID. You may sign up online at enroll.allclearid.com or by phone by calling«DID_Phone» using the following redemption code: {RedemptionCode}.

Please note: Additional steps may be required by you in order to activate your phone alerts and monitoringoptions.

[REQUIRED PRODUCT/SERVICE LANGUAGE END]

We at Vapourbeauty.com, take the protection of your personal information seriously and are taking steps toprevent a similar occurrence. We have been working with Aptos to learn more about the incident. Aptoshas indicated that it has worked with a leading cybersecurity firm to remove the malware from its systemsand is actively monitoring the platform to safeguard personal information.

For More InformationWe have limited information to share beyond what is provided in this notice and still we understand thatyou may have additional questions or concerns. Please feel free to reach out to our dedicated hotline atAllClear ID Monday through Saturday, 8 a.m. to 8 p.m. Central Time at 1-855-336-6688 and AllClear IDwill work with you to address your questions and concerns

Sincerely,

[Tera Romero, Records][Vapour Organic Beauty ][PO BOX 99 TAOS, NM 87571]