HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLOCATIONBEHAVIORMETADATALowContained
Awes.me, Inc.
bd_c13fe9ab3ec3e425 · schema v1 · pii pii-v1
Full breach record for Awes.me, Inc. →Awes.me, Inc. (Flickr) disclosed a security issue involving a third-party email service provider. On February 5, 2026, the company was alerted to a vulnerability that may have allowed unauthorized access to member information, including names, email addresses, usernames, account types, IP addresses, general location, and activity data. Passwords and payment card numbers were not affected. Access to the affected system was disabled within hours. The company is conducting a review and strengthening security practices with third-party providers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-618261
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2026
- Raw hash
- d2e11778b16c4b638749e5c5e922bae8c4f2539720afab20a6ae47dcb20a2a3c
Reporting entity
- Name
- Awes.me, Inc.norm: awesme
- Domain
- flickr.com
Victim entity
- Name
- Awes.me, Inc.norm: awesme
- Domain
- flickr.com
Incident
- Discovered
- Feb 5, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICLOCATIONBEHAVIORMETADATA
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Regulator citations
- Notified the relevant data protection authorities
- Third party
- via email service provider
- Initial access
- supply_chain
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.