HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICCREDENTIALSLowContained
Evite, Inc.
bd_3b560f1474b88ebe · schema v1 · pii pii-v1
Full breach record for Evite, Inc. →Evite, Inc. notified Delaware AG of a data breach involving unauthorized access to an inactive data storage file. The incident involved malicious activity starting February 22, 2019, discovered by Evite on April 15, 2019. The file contained user names, usernames, email addresses, passwords, and optional PII (DOB, phone, address) created up through 2013. Evite engaged forensic consultants, coordinated with law enforcement, enhanced security, and reset passwords. No evidence of misuse was found.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_09c5bde79facb84bCalifornia State AGfiled 2019-06-06(4d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2019/07/Customer-Notice-Evite.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2019
- Raw hash
- f9b988becb60567e2612a20300dedea4d56d2ccbf49cdb1c6a12434e90766960
Reporting entity
- Name
- Evite, Inc.norm: evite
- Domain
- evite.com
Victim entity
- Name
- Evite, Inc.norm: evite
- Domain
- evite.com
Incident
- Discovered
- Apr 15, 2019
- Materiality determined
- —
- Notification sent
- Jun 10, 2019
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Coordinated with law enforcement regarding the incident
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.