MalwareRansomwareData EncryptedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Divvy
bd_6a530a38e06eba6b · schema v1 · pii pii-v1
Full breach record for Divvy →Divvy Up, Inc. reported a data breach involving its website hosting provider. Malware was downloaded to the hosted website, compromising payment transactions between December 1, 2020, and March 8, 2021. Affected data included names, addresses, and payment card details (number, CVC, expiration). The company engaged forensic experts, removed malware, and upgraded security protocols.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3e0b7231e130092bOregon State AGfiled 2021-05-03Candidate
- bd_3fb2bd19bcf8bf84Montana State AGfiled 2021-05-03Verified
- bd_8fc9f6edf9594d0bWashington State AGfiled 2021-05-03Verified
- bd_f2b3150d821352fbWashington State AGfiled 2021-05-03Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_c0c5e3cb53ac3092Maine State AGfiled 2021-05-04(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-540501
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2021
- Raw hash
- 5dcb958a5850362fad71c650edf16be5d4615d0c47c5f64aa8dfc817d09b1a39
Reporting entity
- Name
- Divvynorm: divvy
- Domain
- divvy.app
Victim entity
- Name
- Divvynorm: divvy
- Domain
- divvy.app
Incident
- Discovered
- Mar 10, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1486 Data Encrypted for Impact
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.