MalwareRansomwareData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Divvy
bd_5974d6aca33ca5d9 · schema v1 · pii pii-v1
Full breach record for Divvy →Divvy Up, Inc. reported a data breach involving its website hosting provider. Malware was downloaded to the hosted website, compromising payment transactions between May 10, 2020, and June 18, 2021. Affected data included names, addresses, and payment card details (number, CVC, expiration). PayPal transactions remained secure. Divvy Up engaged a security service, removed malware, upgraded protocols, and restricted payments to PayPal.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e80e9f81608676a8Montana State AGfiled 2021-07-30Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-543412
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 30, 2021
- Raw hash
- 8374a44c7e82b4619d3a5d4abbd2cf194b278584f9b67ebcf7620eea44a9efac
Reporting entity
- Name
- Divvynorm: divvy
- Domain
- divvy.app
Victim entity
- Name
- Divvynorm: divvy
- Domain
- divvy.app
Incident
- Discovered
- Jun 18, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1486 Data Encrypted for Impact
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.