HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
Shutterfly, Inc.
bd_11d7d5910ae89456 · schema v1 · pii pii-v1
Full breach record for Shutterfly, Inc. →Shutterfly, Inc. reported a cybersecurity incident involving unauthorized access to its Workday test environment. On January 11, 2018, a Shutterfly employee's credentials were used without authorization to access the test environment. The breach potentially exposed employee and dependent data, including names, SSNs, dates of birth, and financial account numbers. No customer or vendor data was impacted. Shutterfly engaged forensic investigators, notified law enforcement, and offered one year of Experian Identity Works Premium to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134863
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 28, 2018
- Raw hash
- b77f36ae08f06c2746bde4fac4bb52088fc585d103e5deabfdfd8b68033dcde3
Reporting entity
- Name
- Shutterfly, Inc.norm: shutterfly
- Domain
- shutterfly.com
Victim entity
- Name
- Shutterfly, Inc.norm: shutterfly
- Domain
- shutterfly.com
Incident
- Discovered
- Mar 20, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.