HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Rocket Lawyer Incorporated
bd_2af2645bc1185e20 · schema v1 · pii pii-v1
Full breach record for Rocket Lawyer Incorporated →Rocket Lawyer, via data maintainer Legalinc, disclosed a breach involving a vulnerability in a customer database. The incident, discovered in Dec 2019, potentially exposed names, addresses, government IDs, and SSNs of individuals who formed businesses. Legalinc engaged forensic investigators, remediated the vulnerability, and offered one year of identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-186061
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 15, 2020
- Raw hash
- 584e8fa15f25be5756453886887da8d4adabdb4eb92cb0c0a5f45be906414b44
Reporting entity
- Name
- Legalinc Corporate Service Inc.norm: legalinc corporate service
Victim entity
- Name
- Rocket Lawyer Incorporatednorm: rocket lawyer
Incident
- Discovered
- Dec 4, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.