Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesHanna Andersson said malware on its third-party ecommerce platform may have captured information entered during online purchases between September 16 and November 11, 2019. The company’s January 15, 2020 notice said names, shipping and billing addresses, payment-card numbers, CVVs, and expiration dates were potentially involved. The public record cited here does not establish how many people’s data was actually obtained.
What happened in the Hanna Andersson breach?
Hanna Andersson’s investigation found malware on the third-party Salesforce Commerce Cloud platform used for online purchases. The malware may have scraped purchase information, according to a description of the investigation in a 2020 federal court filing. That wording is qualified: the public sources do not establish that every listed field was captured for every customer.
The filing’s account of a notice to state attorneys general says law enforcement alerted the company on December 5, 2019, that cards used on the website were being offered for sale on a dark-web site. Hanna’s customer notice said it retained forensic experts and cooperated with law enforcement and payment-card brands.
When did the breach happen?
| Date | What the public record says |
|---|---|
| September 16, 2019 | Start of the potential compromise period identified in the customer notice; California’s breach-notice listing also records this as the breach date. |
| November 11, 2019 | End of the purchase window named in Hanna’s notice. A contemporaneous report said malware had been removed by this date. |
| December 5, 2019 | Law enforcement reportedly informed Hanna that cards used on its site were available for sale online. |
| January 15, 2020 | Date of Hanna’s customer notice and the report date recorded in California’s listing. |
| November 19, 2020 | Plaintiffs filed a memorandum supporting a motion for preliminary approval of a proposed settlement. |
What information may have been exposed?
Hanna’s January 15, 2020 customer notice said the incident potentially involved information submitted during the final purchase process:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- Name
- Shipping address
- Billing address
- Payment-card number
- CVV code
- Card expiration date
A court filing also described other checkout fields, including telephone number, email address, cardholder name, and card type. Those are fields the filing says were collected during checkout; they are not all included in the customer notice’s list of information potentially involved. The notice does not establish that every customer’s information, or every field listed, was acquired.
What is known about the attackers and how they got in?
The public information cited in contemporaneous SecurityWeek coverage did not identify who was responsible, explain how malicious code reached the ecommerce platform, or confirm a specific attack group. Magecart attribution was not confirmed. The available evidence supports describing the incident as malware on a third-party ecommerce platform that may have scraped purchase information—not naming a particular group or asserting a proven point of entry.
How did Hanna Andersson respond?
In its customer notice, Hanna said it had taken steps to re-secure and further harden its online purchasing platform, retained forensic experts, and cooperated with law enforcement and payment-card brands. The account in the court filing also described increased use of multifactor authentication and enhanced system monitoring. These are reported response measures, not independently audited results.
The notice offered identity-theft protection through ID Experts’ MyIDCare service. That was a historical offer; current enrollment availability is not established by the sources cited here.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What did the proposed settlement provide?
A November 19, 2020 plaintiffs’ memorandum supporting preliminary approval described proposed terms, not a confirmed final outcome. It estimated a class of approximately 200,273 U.S. residents who purchased from the website between September 16 and November 11, 2019, and proposed a $400,000 fund.
| Proposed term in the 2020 filing | What it meant |
|---|---|
| Basic Award | Up to $500, subject to the settlement’s claims and allocation terms. |
| Reimbursement Award | Up to $5,000, subject to the settlement’s claims and allocation terms. |
| Security measures | Proposed steps included a NIST Risk Management Framework-aligned risk assessment, multifactor authentication for cloud-service accounts, and alerts for new cloud accounts. |
The approximately 200,273 figure was an estimate of the proposed settlement class, not a verified count of people whose information was obtained. The filing alone does not establish final approval, payments distributed, or current claim availability.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should customers do?
If you made an online purchase from Hanna Andersson during the stated period, use the company’s original notice for incident-specific information and contact the card issuer for advice about your account. Review payment-account activity and promptly report charges you do not recognize. Do not assume that the historical MyIDCare offer can still be enrolled in today.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

