NetGalley Home
bd_2b05013c93b95c98 · schema v1 · pii pii-v1
Full breach record for NetGalley Home →On December 21, 2020, NetGalley experienced a data security incident where a hacker accessed a backup file of the NetGalley database stored in Amazon Cloud. The breach occurred because a testing server was left unsecured, making credentials easily attainable. Exposed information included login names, passwords, first/last names, email addresses, countries, and optionally bios, mailing addresses, phone numbers, birthdays, company names, and Kindle email addresses. No financial information was involved. NetGalley re-secured testing sites, revised backup procedures, changed legacy passwords, added security features, and required password resets. The FBI was notified.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 21, 2020
Begins
Dec 21, 2020
Discovered
Dec 23, 2020
Filed
vs. sector median
18 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.