Back-to-Back FabFitFun Data Breaches

Posted on behalf of Arnold Law Firm in

NOTICE: If you received a NOTICE OF DATA BREACH from popular subscription box retailer FabFitFun, contact the Arnold Law Firm at (916) 777-7777.

cyber-attack-redFabFitFun recently announced consecutive cybersecurity incidents involving customer payment information. The popular lifestyle ecommerce retailer discovered that an unauthorized third party inserted malicious code on their website designed to capture information associated with customer sign ups.

The company began to notify affected customers on September 18 by email and USPS mail delivery. The data breach appears to have affected new members who signed up during the periods between:

  • April 26, 2020 and May 14, 2020; and
  • May 22, 2020 and August 3, 2020.

For customers who used credit or debit cards to set up their subscription account, compromised information may include:

  • Names
  • Email addresses
  • Account passwords
  • Addresses
  • Payment card account numbers
  • Card expiration dates
  • Card verification codes

For customers who used PayPal or Apple Pay, FabFitFun claims that only email addresses and FabFitFun passwords were involved in the data breach.

Despite consecutive data breaches, FabFitFun claims to have taken appropriate steps to secure their website and reported the matter to law enforcement. The company is offering affected customers one year of identity protection and a $25 credit, which requires a current FabFitFun membership and expires by the end of the year.

Remarks on multiple online forums show that consumers are unhappy about the FabFitFun security incidents and how they have been handled.

According to Josey, “So…they knew back in June that they were hacked. It was posted on their community board. They wouldn’t address the question! Now they are suddenly saying it happened again?!”

Anna commented, “…they were warned they had a breach and denied it. I’m very disappointed in their statement because a customer or more made them aware of the first breach they did nothing and let a second happen.”

Users on Reddit made various claims that weeks went by without notification of the breach, despite customers noticing fraudulent credit card transactions and attempts to use their personal information to sign up for shopping accounts at other retailers.

Initially founded in 2010 as an online magazine focused on beauty, fitness and fashion, FabFitFun expanded into subscription box marketing three years later – an industry that has grown at a compound annual growth rate of nearly 60 percent.

The company claims to now have more than 1 million members worldwide. Its main offering is their FabFitFun Box, a curated collection of products across beauty, fashion, wellness, fitness, home and technology categories delivered four times per year. The box is priced at $50 per season or $180 per year.

FabFitFun annual revenues are estimated at $300 million.

NOTICE: If you received a NOTICE OF DATA BREACH from FitFabFun, contact the Arnold Law Firm at (916) 777-7777 to discuss your situation and possible developing legal options.

Settlement - $3,767,000

Truck Accident

A 20-year-old man who had been married for just 12 days left home on his way to work. He was driving on Pleasant Grove Road in Sutter County in the early morning when he came upon a slow-moving truck. As he pulled out to pass the truck, the truck driver turned left in front of him. The young man attempted to steer back into his lane but his vehicle struck an un-flagged piece of metal extending from the back of the truck. He died in the resulting crash.

Expert witnesses brought in by the Arnold Law Firm proved that the truck, owned and operated by a hauling firm, should never have been on the highway that morning. Specifically, the rear and side turn signals did not work and the rear-view mirror was in a poor state of adjustment at the time of the collision. As a result, the driver, who had failed to properly inspect the vehicle before setting out that morning, couldn’t see the young man’s vehicle as it attempted to pass.

The poor condition of the truck, its lack of maintenance and the manner in which it was operated were found to be substantial factors in causing the collision that killed the young man. The testimony also established that the man had been making a lawful pass at the lawful speed limit and acted reasonably when he attempted to avoid the collision.

The man’s 20-year-old widow was awarded $3,767,000.77, his parents were awarded $185,131 and the family was reimbursed $11,899 in funeral expenses. Though money is a poor substitute for a young man’s life, this verdict demonstrates that drivers who endanger the lives of others will be held accountable for their actions.