HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
SHIFT TECHNOLOGIES, INC.
bd_33cb39d5a96cf11d · schema v1 · pii pii-v1
Full breach record for SHIFT TECHNOLOGIES, INC. →Shift Technologies, Inc. reported a data breach involving unauthorized access to cloud storage by a third-party vendor operating its website. The incident occurred on September 17, 2020, and was discovered on September 18, 2020. While the scope of accessed data is uncertain, personal information of California residents may have been involved. Shift engaged forensic investigators, secured the system, and offered complimentary identity monitoring via Experian.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_bd7750ed742ec875Montana State AGfiled 2021-01-14Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-198531
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2021
- Raw hash
- 0f6abb5d174121b3326b2d54f1d7f76a1f3eb4eb876c58a060c9cff23c0f5194
Reporting entity
- Name
- SHIFT TECHNOLOGIES, INC.norm: shift technologies
Victim entity
- Name
- SHIFT TECHNOLOGIES, INC.norm: shift technologies
Incident
- Discovered
- Sep 18, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 weeks(118 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.