Shutterfly, Inc.
ent_019e10ba7dfdc4546e5b35b2a14114a4
Disclosures
11
Leak Site · State AG · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
52,777
as filed · State AG OR
Leak-site claims
3
unverified actor claims
Identity resolution
- Canonical name
- Shutterfly, Inc.
- Normalized
- shutterfly— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300I1C8WJQ5FZE154
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- shutterfly.com
Disclosure history (11)newest first
- GLOBALLeak Siteas victim2023-07-13
Shutterfly: Photo Books, Cards, Prints, Wall Art, Gifts, Wedding
- 🦞Maine State AGas victim2022-06-03
Shutterfly, LLC reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on December 3, 2021. The breach was discovered on December 13, 2021. The incident affected 70 Maine residents, compromising their names and Social Security numbers. Shutterfly began notifying affected individuals on March 2, 2022, and offered 24 months of credit monitoring services through Equifax.
- 🐻California State AGas victim2022-06-02
Shutterfly, LLC experienced a ransomware attack on or about December 3, 2021, discovered on December 13, 2021. An unauthorized third party gained access to the network, locking systems and accessing data including names and employment-related information (salary, compensation, FMLA, workers' comp). Shutterfly engaged outside cybersecurity experts, notified law enforcement, and offered two years of free Equifax credit monitoring.
- 🦫Oregon State AGas victim2022-05-26
Shutterfly, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2022-05-26. The breach occurred during 12/3/2021 - 12/15/2021. The breach was discovered on 12/13/2021. 52,777 individuals were affected. Notice was sent on 2/18/20223/14/20225/12/2022.
- 🌲Washington State AGas victim2022-05-26
Shutterfly, LLC, a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2021-12-13 and filed notice on 2022-05-26. 1,273 Washington residents were affected. 164 days elapsed between awareness and notification. 10 days to identify the breach. 2 days to contain the breach.
- 🐻California State AGas victim2022-03-23
Shutterfly, LLC reported a ransomware attack on December 3, 2021, discovered on December 13, 2021. The attacker encrypted systems and exfiltrated personal data, including names and potentially sensitive employment information (salary, compensation, FMLA, workers' comp). Shutterfly engaged outside cybersecurity experts, notified law enforcement, and provided two years of free Equifax credit monitoring to affected individuals.
- 🦬Montana State AGas victim2022-03-22
Shutterfly reported a data breach to the Montana Attorney General. The breach was reported on 2022-03-22. The breach occurred from 12/3/2021 to 12/13/2021. 71 Montana residents were affected.
- GLOBALLeak Siteas victim2022-01-15
- GLOBALLeak Siteas victim2020-09-05
shutterfly.com
- 🐻California State AGas victim2018-03-28
Shutterfly, Inc. reported a cybersecurity incident involving unauthorized access to its Workday test environment. On January 11, 2018, a Shutterfly employee's credentials were used without authorization to access the test environment. The breach potentially exposed employee and dependent data, including names, SSNs, dates of birth, and financial account numbers. No customer or vendor data was impacted. Shutterfly engaged forensic investigators, notified law enforcement, and offered one year of Experian Identity Works Premium to affected individuals.
- 🐻California State AGas victim2014-11-26
Shutterfly, Inc. (operating Tiny Prints, Treat, and Wedding Paper Divas) notified the California AG of a cyberattack detected in November 2014. The incident potentially exposed customer email addresses and encrypted passwords. Credit card data was encrypted and not compromised. The company engaged security experts and federal law enforcement.