Ancestry.com Operations, Inc.
bd_9e52af991ea46d8c · schema v1 · pii pii-v1
Full breach record for Ancestry.com Operations, Inc. →Ancestry.com Operations, Inc. disclosed that a security researcher reported a file containing 300,000 RootsWeb username/email and password combinations. The incident was discovered on December 20, 2017. Approximately 55,000 users had overlapping credentials with Ancestry commercial sites. Ancestry locked affected accounts, took RootsWeb offline, and initiated a forensic investigation. No sensitive financial or government ID data was exposed.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 20, 2017
Discovered
Dec 23, 2017
Filed
vs. sector median
18 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.