AccidentalMisconfigurationSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
SaveDay, Inc.
bd_78bc62373964f41e · schema v1 · pii pii-v1
Full breach record for SaveDay, Inc. →SaveDay, Inc. disclosed a data vulnerability involving its technology vendor, Söoryen Technologies, on July 5, 2019. A performance test site on Amazon Web Services was exposed, potentially allowing unauthorized access to client and participant data. Affected data included names, addresses, dates of birth, social security numbers, telephone numbers, and email addresses. SaveDay immediately removed the test site and is implementing additional security measures and testing protocols. Credit monitoring services are being considered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-149374
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 31, 2019
- Raw hash
- cdf61b9b4267305de3a0702a3e79f61c2b4c13fdb500ae4e22265b706122fd80
Reporting entity
- Name
- SaveDay, Inc.norm: saveday
- Domain
- saveday.com
Victim entity
- Name
- SaveDay, Inc.norm: saveday
- Domain
- saveday.com
Incident
- Discovered
- Jul 5, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- Regulator citations
- Notifying all relevant regulatory agencies
- Third party
- via Söoryen Technologies
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.