AccidentalMisconfigurationCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumResolved
AVALARA, INC.
bd_5377a486edec37a5 · schema v1 · pii pii-v1
Full breach record for AVALARA, INC. →Avalara, Inc. disclosed a data breach involving the eCompli software application, acquired from Compli, Inc. On May 22, 2019, a former Compli employee notified Avalara of a vulnerability that allowed unauthorized access to personal information of certain individuals at Avalara's customers. The exposed data included names, SSNs, driver's license numbers, dates of birth, and employment history. The third party deleted the accessed data and certified it was not shared. Avalara removed the vulnerability, investigated the scope, and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-147956
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 7, 2019
- Raw hash
- 06c12f975af1a2b23d33696ea5a052070ef37fc6bfa6a23c56589bc7ea602695
Reporting entity
- Name
- AVALARA, INC.norm: avalara
Victim entity
- Name
- AVALARA, INC.norm: avalara
Incident
- Discovered
- May 22, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Misconfiguration
- Threat actor
- External
- Third party
- via Compli, Inc. employee
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.