ReverbNation
bd_2f9ae7cf1ee13c96 · schema v1 · pii pii-v1
ReverbNation notified users in September 2015 that a vendor's computer systems were illegally accessed between January and May 2014. The breach exposed user names, SSNs, encrypted passwords, and contact info. Law enforcement was involved, and the attacker was charged. Users were advised to change passwords and monitor credit reports.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2014
Begins
Jan 1, 2014
Discovered
Sep 17, 2015
Filed
vs. sector median
+70 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_52b44d209cd799602015-09-18 · +1dVerified
- California State AGbd_9316a34c0226ad422015-09-02 · +15dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 2 (CA), last Sep 18 (MA) — a 16-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.