HackingStolen CredentialsCustomer Data InvolvedCREDENTIALSIDENTITY_BASICLowContained
Havenly
bd_38976802f335e279 · schema v1 · pii pii-v1
Full breach record for Havenly →Havenly, Inc. reported that an outside individual gained unauthorized access to a database containing usernames and hashed passwords of users on or around June 25, 2020. The affected data included first and last names, account usernames, and hashed passwords. No credit card numbers or billing addresses were stored or affected. Havenly logged out all users, forced password resets, and engaged a forensic firm on July 29, 2020.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193576
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 31, 2020
- Raw hash
- 377b2d4fea698ff1b0c05d7726ee4f4a14cac193bfaf2a979256b065cc2b9a58
Reporting entity
- Name
- Havenlynorm: havenly
- Domain
- havenly.com
Victim entity
- Name
- Havenlynorm: havenly
- Domain
- havenly.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 29, 2020
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Been in contact with federal law enforcement regarding this matter
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.