AccidentalMisconfigurationCustomer Data InvolvedFINANCIAL_ACCOUNTCREDENTIALSLowContained
Zulily, Inc.
bd_ec59f3b17c8c3fe9 · schema v1 · pii pii-v1
Full breach record for Zulily, Inc. →Zulily, LLC reported a data security breach in California involving a checkout page code error between February 23, 2022, and June 15, 2022. The misconfiguration caused transaction data, including payment card numbers and verification codes, to be sent to an unauthorized payment processor. Zulily corrected the code, notified processors, and issued refunds for duplicate shipping charges. No specific number of affected individuals was disclosed.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3c2a0b3c2997f9b5Maine State AGfiled 2022-07-22Candidate
- bd_430b9bf43cf0ad63Montana State AGfiled 2022-07-22Verified by operator
- bd_d4316952ca18512eOregon State AGfiled 2022-07-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555541
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2022
- Raw hash
- 1958bfbc2838d1e42bf7c3f67a5be03acc61632b9a7e3379de7cc123927f509a
Reporting entity
- Name
- Zulily, Inc.norm: zulily
Victim entity
- Name
- Zulily, Inc.norm: zulily
Incident
- Discovered
- Jun 26, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.