Zola, Inc.
bd_45f7b8b1b0320be3 · schema v1 · pii pii-v1
Full breach record for Zola, Inc. →Zola, Inc. notified users of a credential stuffing incident beginning May 20, 2022. Attackers used stolen credentials from other breaches to access Zola accounts. Compromised data included names, purchase history, shipping addresses, phone numbers, Zola store credit, and partial payment/bank details. Zola reset all user passwords and engaged external security firms.
J jump to incidentP pin to compareR raw source
Incident timeline
May 20, 2022
Begins
May 21, 2022
Discovered
Jul 5, 2022
Filed
vs. sector median
12 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_af718cd2b674b7012022-07-05Verified
- Massachusetts State AGbd_e0cfe06e42fe1f832022-07-05Verified
- Maine State AGbd_a844ea2b795ac2fc2022-07-04 · +1dVerified
- Maine State AGbd_2f5533f430a9894b2022-06-21 · +14dCandidate
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Jun 21 (ME), last Jul 5 (MT) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.