HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Stripe GEP, Inc.
bd_9d6a179edc0c075c · schema v1 · pii pii-v1
Full breach record for Stripe GEP, Inc. →Stripe GEP, Inc. (via service provider Legalinc Corporate Services, Inc.) disclosed a security vulnerability in its document storage system affecting Stripe Atlas users. The breach potentially exposed personal information, including names and Social Security numbers, for approximately 2,670 individuals between October 2017 and December 2019. No evidence of misuse was found, but affected individuals were offered one year of complimentary credit monitoring and identity protection services through Experian.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e0637c912610d8ffMontana State AGfiled 2019-12-31Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-185511
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 31, 2019
- Raw hash
- 6df72c615d50e8f3c3105fe4db635b56be7b5d686c0d2feeb330a3dcc8cf2a87
Reporting entity
- Name
- Legalinc Corporate Service Inc.norm: legalinc corporate service
Victim entity
- Name
- Stripe GEP, Inc.norm: stripe gep
Incident
- Discovered
- Dec 11, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,670
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.