Shutterfly, Inc.
ent_019e10ba7dfdc4546e5b35b2a14114a4
Disclosures
19
Leak Site · State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
52,777
nationwide · State AG ME
Leak-site claims
3
unverified actor claims
Identity resolution
- Canonical name
- Shutterfly, Inc.
- Normalized
- shutterfly— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300I1C8WJQ5FZE154
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- shutterfly.com
Disclosure history (19)newest first
- GLOBALLeak Siteas victim2023-07-13
Shutterfly: Photo Books, Cards, Prints, Wall Art, Gifts, Wedding
- New Hampshire State AGas victim2022-06-06
Shutterfly, LLC filed a supplemental notice with the New Hampshire Attorney General regarding a ransomware incident. The breach, occurring around Dec 3, 2021 and discovered Dec 13, 2021, affected approximately 158 NH residents (plus 1 previously notified). Data exposed included names, SSNs, DOB, financial account/routing numbers, medical/health insurance info, and employment data. Notices were sent March 14, 2022, offering 24 months of credit monitoring.
- Maine State AGas victim2022-06-03
Shutterfly, LLC reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on December 3, 2021. The breach was discovered on December 13, 2021. The incident affected 70 Maine residents, compromising their names and Social Security numbers. Shutterfly began notifying affected individuals on March 2, 2022, and offered 24 months of credit monitoring services through Equifax.
- California State AGas victim2022-06-02
Shutterfly, LLC experienced a ransomware attack on December 3, 2021, discovered on December 13, 2021. An unauthorized third party accessed the network, locking systems and accessing personal data including names and potential employment information such as salary and compensation. Shutterfly engaged cybersecurity experts, notified law enforcement, and offered two years of free credit monitoring via Equifax.
- Oregon State AGas victim2022-05-26
Shutterfly, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2022-05-26. The breach occurred during 12/3/2021 - 12/15/2021. The breach was discovered on 12/13/2021. 52,777 individuals were affected. Notice was sent on 2/18/20223/14/20225/12/2022.
- Washington State AGas victim2022-05-26
Shutterfly, LLC reported a ransomware attack by the Conti group affecting 1,273 Washington residents. Unauthorized access occurred Dec 3, 2021; discovered Dec 13, 2021. Exposed data included PII, SSNs, financial accounts, health info, and credentials. Shutterfly engaged forensic experts, notified law enforcement, and provided 24 months of credit monitoring.
- CALIFORNIAHHS OCRas victim2022-05-03
Shutterfly, LLC reported to HHS on 2022-05-03 a Unauthorized Access/Disclosure affecting 2641 individuals. Breached information located on Paper/Films. An employee mailed PHI to wrong recipients.
- California State AGas victim2022-03-23
Shutterfly experienced a ransomware attack on December 3, 2021, discovered on December 13, 2021. An unauthorized third party accessed the network, locking systems and accessing personal data including names, potential financial account numbers, and employment information such as salary and FMLA leave details. Shutterfly engaged cybersecurity experts, notified law enforcement, and offered two years of free credit monitoring via Equifax.
- Montana State AGas victim2022-03-22
Shutterfly Inc. disclosed a ransomware attack occurring on or about December 3, 2021, discovered on December 13, 2021. The incident involved unauthorized access to systems and exfiltration of personal information, including names and employment-related data. Shutterfly engaged outside cybersecurity experts, notified law enforcement, and offered two years of free credit monitoring via Equifax.
- New Hampshire State AGas victim2022-02-28
Shutterfly, LLC notified the New Hampshire Attorney General of a ransomware attack by the Conti group. Access began Dec 3, 2021; discovered Dec 13, 2021. One NH resident's PII (name, address, SSN, DOB) was affected. Shutterfly engaged forensic experts, notified law enforcement, and offers 2 years of Equifax credit monitoring. Filing is a supplemental notice.
- Massachusetts State AGas victim2022-02-25
Shutterfly, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-02-25. 678 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2022-02-22
Shutterfly, LLC notified the NH Attorney General of a Conti ransomware attack. Unauthorized access began approx. Dec 3, 2021; discovered Dec 13, 2021. One NH resident affected with PII (SSN, DOB, financial accounts). Remediation included MFA, password resets, and hardening. Investigation ongoing.
- GLOBALLeak Siteas victim2022-01-15
- Indiana State AGas victim2021-12-18
Shutterfly, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2021-12-03 and was reported on 2021-12-18. 1,678 Indiana residents were affected. 52,777 individuals affected in total.
- GLOBALLeak Siteas victim2020-09-05
shutterfly.com
- California State AGas victim2018-03-28
Shutterfly, Inc. reported unauthorized access to its Workday test environment on January 11, 2018, discovered on March 20, 2018. An employee's credentials were used without authorization. Potentially exposed data included names, SSNs, DOBs, bank account/routing numbers, and dependent info for employees and beneficiaries. No customer data was impacted. Shutterfly engaged forensic investigators, notified law enforcement, and offered one year of identity protection via Experian.
- New Hampshire State AGas victim2018-03-28
Shutterfly, Inc. notified the NH AG of unauthorized access to a Workday test database on Jan 11, 2018, discovered Mar 20, 2018. Access was via fraudulent employee credentials. Data included NH residents' names, SSNs, DOB, bank accounts, and salary. 6 NH residents affected. Shutterfly engaged forensic investigators, notified law enforcement, and offered 1-year credit monitoring.
- Massachusetts State AGas victim2018-03-28
Shutterfly reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-03-28. 89 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2014-11-26
Shutterfly, Inc. (operating Tiny Prints, Treat, and Wedding Paper Divas) notified the California AG of a cyberattack detected in November 2014. The incident potentially exposed customer email addresses and encrypted passwords. Credit card data was encrypted and not compromised. The company engaged security experts and federal law enforcement.