MalwareProfessional ServicesProfessional ServicesRansomwareRansom DemandedData EncryptedDelayed DiscoveryMedium
Shutterfly, Inc.
bd_730635c53186a9da · schema v1 · pii pii-v1
Full breach record for Shutterfly, Inc. →Shutterfly, LLC, a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2021-12-13 and filed notice on 2022-05-26. 1,273 Washington residents were affected. 164 days elapsed between awareness and notification. 10 days to identify the breach. 2 days to contain the breach.
Washington clock✗ WA AG >90d23 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 5 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 628 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_00a015de4f622b87Leak Sitecontifiled 2022-01-15(131d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_2ef1fe515d65166aOregon State AGfiled 2022-05-26Verified by operator
- bd_98318e1dead7508eCalifornia State AGfiled 2022-06-02(7d gap)Verified by operator
- bd_82f36a2eea2523fcMaine State AGfiled 2022-06-03(8d gap)Verified
Source provenance
- Source URL
- https://data.wa.gov/resource/sb4j-ca4h.json?id=13447
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2022
- Raw hash
- ccccc0fc86295040c65b81ff5ed1b758ba611e5fc5b13488d90b2679528a6de9
Reporting entity
- Name
- Shutterfly, Inc.norm: shutterfly
- Domain
- shutterfly.com
Victim entity
- Name
- Shutterfly, Inc.norm: shutterfly
- Domain
- shutterfly.com
- Industry
- Professional Servicesllm
Incident
- Discovered
- Dec 13, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,273
- Data types
- —
- Attack vector
- Ransomware
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 23 weeks(164 days from discovery to filing)
- Compliance flags
- WA AG >90dLeak >180d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.