HackingCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Groupon, Inc.
bd_7116f7564a2cd57e · schema v1 · pii pii-v1
Full breach record for Groupon, Inc. →LivingSocial, Inc. reported a cyber-attack on April 5, 2013, resulting in unauthorized access to customer data including names, email addresses, dates of birth, and encrypted passwords. Credit card information was not accessed. The company expired old passwords and requested customers create new ones, while working with law enforcement on the investigation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-41617
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 26, 2013
- Raw hash
- 655af40ebbc124101ca7dada88abe10e0163c455f9c124870c798bd310e69694
Reporting entity
- Name
- Groupon, Inc.norm: groupon
- Domain
- groupon.com
Victim entity
- Name
- Groupon, Inc.norm: groupon
- Domain
- groupon.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.