Shutterfly, Inc.
bd_11d7d5910ae89456 · schema v1 · pii pii-v1
Full breach record for Shutterfly, Inc. →5 incidents on fileShutterfly, Inc. reported unauthorized access to its Workday test environment on January 11, 2018, discovered on March 20, 2018. An employee's credentials were used without authorization. Potentially exposed data included names, SSNs, DOBs, bank account/routing numbers, and dependent info for employees and beneficiaries. No customer data was impacted. Shutterfly engaged forensic investigators, notified law enforcement, and offered one year of identity protection via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 11, 2018
Begins
Mar 20, 2018
Discovered
Mar 28, 2018
Filed
vs. sector median
17 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_cb80ce623280cd262018-03-28Verified
- Massachusetts State AGbd_d155b1c960bb7a5d2018-03-28Verified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.