Shiftster LLC
bd_ff21d2f05f75d28d · schema v1 · pii pii-v1
Full breach record for Shiftster LLC →Shiftster LLC (dba ESHYFT) notified consumers of a March 2025 unauthorized access to an AWS S3 bucket. Data potentially exposed included names, DOBs, addresses, VINs, and certain health information. No SSN was impacted. The incident was discovered via a 'cyber security researcher' notification. No evidence of misuse was found.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 12, 2025
Discovered
Oct 20, 2025
Filed
vs. sector median
+13 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_5cc76677f65bb4ba2025-10-22 · +2dVerified
- Massachusetts State AGbd_ace2ab60adfc2fa82025-10-17 · +3dVerified
- Indiana State AGbd_60fc09f62fe686ca2025-08-27 · +54dCandidate
- Nebraska State AGbd_366421f6b471efc52025-08-08 · +73dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Aug 8 (NE), last Oct 22 (NH) — a 75-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.