HackingCustomer Data InvolvedIDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNTLowContained
TaskRabbit, Inc.
bd_eb27196153c239ef · schema v1 · pii pii-v1
Full breach record for TaskRabbit, Inc. →TaskRabbit, Inc. notified South Carolina consumers of a cybersecurity incident discovered on April 12, 2018. Unauthorized access compromised names, usernames, passwords, dates of birth, and truncated payment card data. TaskRabbit engaged forensic investigators, reset passwords, and provided one year of identity restoration services via Experian.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_82ea7962b8663782Hawaii State AGfiled 2018-05-18Verified
- bd_f7f9d351d3e38042Oregon State AGfiled 2018-05-16(2d gap)Verified
- bd_2bacd9f8cd21af18California State AGfiled 2018-05-14(4d gap)Verified
- bd_1481d340ac00ffafWashington State AGfiled 2018-05-09(9d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 9d gap
- bd_35cb01ef23965c77Montana State AGfiled 2018-05-09(9d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2018/TaskRabbitInc..pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2018
- Raw hash
- 1b887b194ef60b42f753efb5aec6396ae10f676c5a0c22f974a03ec64d5f3683
Reporting entity
- Name
- TaskRabbit, Inc.norm: taskrabbit
- Domain
- taskrabbit.com
Victim entity
- Name
- TaskRabbit, Inc.norm: taskrabbit
- Domain
- taskrabbit.com
Incident
- Discovered
- Apr 12, 2018
- Materiality determined
- —
- Notification sent
- Apr 13, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.