DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsPhishingSupply Chain (3P Vendor)Data ExfiltratedMulti-Stage ChainIdentity (basic)CredentialsAuthenticationMediumContained

LIVE AUCTIONEERS

bd_f184d059d1ebe760 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 11, 2020

Filed

Sep 3, 2020

To disclose

8 weeks

Affected

38,523state residents only

Confidence

70%
Full breach record for LIVE AUCTIONEERS2 incidents on file

LiveAuctioneers notified Washington AG of a breach affecting 38,523 residents. An unknown hacker exploited a third-party software solution on June 19, 2020, to access the production database via stolen internal credentials. Usernames, hashed passwords (later decrypted), names, emails, and contact details were exposed. LiveAuctioneers notified users starting July 11, 2020, and engaged forensic consultants and the FBI.

Washington clock WA AG >30d8 weeks discovery → filing
notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.

Incident timeline

undetected · 22 days
discovery → filing · 8 weeks / 54 days

Jun 19, 2020

Begins

Jul 11, 2020

Discovered

Sep 3, 2020

Filed

vs. sector median

on median

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed38,523 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.