MalwareRansomwareData ExfiltratedEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICEMPLOYMENTLowActive
Shutterfly, Inc.
bd_412544a89cb7b46a · schema v1 · pii pii-v1
Full breach record for Shutterfly, Inc. →Shutterfly, LLC reported a ransomware attack on December 3, 2021, discovered on December 13, 2021. The attacker encrypted systems and exfiltrated personal data, including names and potentially sensitive employment information (salary, compensation, FMLA, workers' comp). Shutterfly engaged outside cybersecurity experts, notified law enforcement, and provided two years of free Equifax credit monitoring to affected individuals.
Leak gap clock✗ Leak >180d14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 564 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_70ed09c9ac98481bMontana State AGfiled 2022-03-22(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551929
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 23, 2022
- Raw hash
- 8da3c6367e9fd0673fe6662383e19b6d49532b5a2a28338a60e4a3126998526d
Reporting entity
- Name
- Shutterfly, Inc.norm: shutterfly
- Domain
- shutterfly.com
Victim entity
- Name
- Shutterfly, Inc.norm: shutterfly
- Domain
- shutterfly.com
Incident
- Discovered
- Dec 13, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 14 weeks(100 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.