AVALARA, INC.
bd_5377a486edec37a5 · schema v1 · pii pii-v1
Full breach record for AVALARA, INC. →2 incidents on fileAvalara, Inc. disclosed a data breach involving the eCompli software application, acquired from Compli, Inc. On May 22, 2019, a former Compli employee notified Avalara of a vulnerability that allowed unauthorized access to personal information of certain individuals at Avalara's customers. The exposed data included names, SSNs, driver's license numbers, dates of birth, and employment history. The third party deleted the accessed data and certified it was not shared. Avalara removed the vulnerability, investigated the scope, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 22, 2019
Begins
May 22, 2019
Discovered
Jun 7, 2019
Filed
vs. sector median
16 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_9f77ce9ab4c656e02019-06-02 · +5dCandidate
- New Hampshire State AGbd_48ed1e38290146102019-06-13 · +6dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jun 2 (MT), last Jun 13 (NH) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.