HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
WEB.COM GROUP, INC.
bd_127a20deb8e7d77e · schema v1 · pii pii-v1
Full breach record for WEB.COM GROUP, INC. →Web.com Group, Inc. reported a cybersecurity incident where a third party gained unauthorized access to computer systems in late August 2019. The breach affected account information, including names, addresses, phone numbers, and emails, for current and former customers. No credit card data was compromised. Web.com engaged a cybersecurity firm, notified federal authorities, and required password resets for affected users.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7342ebcd55ce9d39Delaware State AGfiled 2019-10-22(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-184127
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2019
- Raw hash
- 0bad529131e0f3f5acc596a8a82ee93b55e080e947c36756dc1a431ca4ea730b
Reporting entity
- Name
- WEB.COM GROUP, INC.norm: webcom group
Victim entity
- Name
- WEB.COM GROUP, INC.norm: webcom group
Incident
- Discovered
- Oct 16, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported the intrusion to federal authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.