HackingCustomer Data InvolvedCREDENTIALSIDENTITY_BASICLowContained
Shutterfly, Inc.
bd_3c5137ca276ad564 · schema v1 · pii pii-v1
Full breach record for Shutterfly, Inc. →Shutterfly, Inc. (operating Tiny Prints, Treat, and Wedding Paper Divas) notified the California AG of a cyberattack detected in November 2014. The incident potentially exposed customer email addresses and encrypted passwords. Credit card data was encrypted and not compromised. The company engaged security experts and federal law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-47602
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 26, 2014
- Raw hash
- e4cbf794fc5158fa1f6db0cc8ffe5f3a377426ccb4e890c83634882719646bce
Reporting entity
- Name
- Shutterfly, Inc.norm: shutterfly
- Domain
- shutterfly.com
Victim entity
- Name
- Shutterfly, Inc.norm: shutterfly
- Domain
- shutterfly.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Nov 26, 2014
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Working with federal law enforcement to assist their investigation of the incident
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.