DisclosureLens
HackingRetail & ConsumerRetailCustomer Data InvolvedCredentialsIdentity (basic)LowContained

Shutterfly, Inc.

bd_3c5137ca276ad564 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Nov 26, 2014

To disclose

Affected

Not disclosed

Confidence

66%
Full breach record for Shutterfly, Inc.5 incidents on file

Shutterfly, Inc. (operating Tiny Prints, Treat, and Wedding Paper Divas) notified the California AG of a cyberattack detected in November 2014. The incident potentially exposed customer email addresses and encrypted passwords. Credit card data was encrypted and not compromised. The company engaged security experts and federal law enforcement.

Incident timeline — partial

? — ?

Breach window unknown

Nov 26, 2014

Filed

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.