AccidentalMisconfigurationCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowResolved
MassageBook
bd_7b8b45dd1a4ebae2 · schema v1 · pii pii-v1
Full breach record for MassageBook →MassageBook (2Book, Inc.), acquired by Togetherwork Holdings, LLC, disclosed a data exposure on July 13, 2023. Personal information, including names, email addresses, hashed passwords, and dates of birth, was stored in plain text in the source code of the client review website. The information was not directly displayed but accessible via source code inspection. A fix was released on July 14, 2023, and users were required to reset passwords. No evidence of unauthorized access was found.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570718
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 24, 2023
- Raw hash
- 70c231dcdef4af7cd764a0dc45eb75bf26584c2103299c682c6aebca84326f3a
Reporting entity
- Name
- TOGETHERWORK HOLDINGS, LLCnorm: togetherwork holdings
Victim entity
- Name
- MassageBooknorm: massagebook
- Domain
- massagebook.com
Incident
- Discovered
- Jul 13, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 11 days(11 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.