HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSMediumContained
DOTERRA INTERNATIONAL, LLC
bd_2143531664cf479b · schema v1 · pii pii-v1
Full breach record for DOTERRA INTERNATIONAL, LLC →dōTERRA International, LLC notified California residents that a third-party vendor providing data hosting and software services experienced an intrusion in March 2016. The incident resulted in the unauthorized acquisition of personal information for some Wellness Advocates and customers, potentially including names, Social Security numbers, payment card information, dates of birth, addresses, phone numbers, and credentials. dōTERRA engaged security firms and law enforcement, and offered 24 months of identity protection and credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_9a87e92b0eb4f9a1Washington State AGfiled 2016-04-18Candidate
- bd_b620c205f026aa44Montana State AGfiled 2016-04-18Verified
- bd_fbb6cfe862b6c98eOregon State AGfiled 2016-05-02(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-61140
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 18, 2016
- Raw hash
- 40f12bf9df94d6d339312347402c0b76d2e5f0d53bab0c6815c018dc547e841b
Reporting entity
- Name
- DOTERRA INTERNATIONAL, LLCnorm: doterra international
Victim entity
- Name
- DOTERRA INTERNATIONAL, LLCnorm: doterra international
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Apr 18, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Third party
- via Third-party vendor
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.