SafetyFirst
bd_8f41a95d9598b81d · schema v1 · pii pii-v1
Full breach record for SafetyFirst →SafetyFirst, a technology services provider, disclosed a data security incident involving an FTP server used to back up driver data. On April 2, 2014, SafetyFirst discovered the server was publicly accessible due to a configuration error during a routine upgrade, resulting in unauthorized access to drivers' personal information. SafetyFirst disconnected the server, engaged forensic investigators, and requested third-party websites remove cached data. The breach exposed names and government identifiers (SSN, driver's license). No evidence of fraud was found. Identity protection services were offered to affected individuals.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-45481
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2014
- Raw hash
- dc0f7c149c521b6c7024526ead49ab44c13bfad12231976f09ca4768c0d2000c
Reporting entity
- Name
- SafetyFirstnorm: safetyfirst
- Domain
- safetyfirst.com
Victim entity
- Name
- SafetyFirstnorm: safetyfirst
- Domain
- safetyfirst.com
Incident
- Discovered
- Apr 2, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.