DisclosureLens
HackingTechnologyInformationCustomer Data InvolvedCredentialsIdentity (basic)HighContained

Ancestry.com Operations, Inc.

bd_9e52af991ea46d8c · schema v1 · pii pii-v1

Severity

High

Discovered

Dec 20, 2017

Filed

Dec 23, 2017

To disclose

3 days

Affected

300,000

Confidence

66%
Full breach record for Ancestry.com Operations, Inc.

Ancestry.com Operations, Inc. disclosed that a security researcher reported a file containing 300,000 RootsWeb username/email and password combinations. The incident was discovered on December 20, 2017. Approximately 55,000 users had overlapping credentials with Ancestry commercial sites. Ancestry locked affected accounts, took RootsWeb offline, and initiated a forensic investigation. No sensitive financial or government ID data was exposed.

California clockDiscovered Dec 20, 2017Notified Dec 23, 20173d CA 60-day OK3 days discovery → filing

Incident timeline

discovery → filing · 3 days

Dec 20, 2017

Discovered

Dec 23, 2017

Filed

vs. sector median

18 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed300,000 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.