HackingTechnologyRetail & ConsumerInformationStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Delayed DiscoveryIDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNTLowContained
Gyft, Inc.
bd_c457021f6f189436 · schema v1 · pii pii-v1
Full breach record for Gyft, Inc. →Gyft, Inc. reported that an unknown party accessed without authorization two cloud providers used by Gyft from October 3 through December 18, 2015. The attacker could view or download user information including names, addresses, dates of birth, phone numbers, email addresses, gift card numbers, and potentially login credentials for users active between March 19 and December 4, 2015. No credit card numbers were compromised. Gyft forced password resets and reset Coinbase tokens for affected users.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_28b6696925d8493fOregon State AGfiled 2016-02-05Verified
- bd_818e629a19d3271bMontana State AGfiled 2016-02-05Verified
- bd_267d04bc79726758Washington State AGfiled 2016-02-04(1d gap)Candidate
- bd_a6a861496184cd87Hawaii State AGfiled 2016-02-09(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59990
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2016
- Raw hash
- a986edcdd0bc5840b565fdae5815e3e1fb7504184a59d1d75d9a37d3935cc431
Reporting entity
- Name
- Gyft, Inc.norm: gyft
Victim entity
- Name
- Gyft, Inc.norm: gyft
- Industry
- TechnologyllmRetail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Feb 4, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage ObjectT1119 Automated CollectionT1074 Data Staged
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.