HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Glofox
bd_f06e14f02c8cb6b0 · schema v1 · pii pii-v1
Full breach record for Glofox →Glofox Inc. reported an unauthorized access incident affecting user data (names, emails, phone numbers, hashed passwords, dates of birth) archived as of March 27, 2020. The breach was discovered on November 14, 2020. Glofox reset passwords, closed the access path, and notified affected administrators. No financial data was compromised.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-196919
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 9, 2020
- Raw hash
- 58686deada167c5012707c348f4b2821cddf38706f1dfca2aae7978d318613b8
Reporting entity
- Name
- Glofoxnorm: glofox
- Domain
- app.glofox.com
Victim entity
- Name
- Glofoxnorm: glofox
- Domain
- app.glofox.com
Incident
- Discovered
- Nov 14, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.