AVALARA, INC.
ent_019ed7fb135ac38601af5f7f6084efab
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
9
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AVALARA, INC.
- Normalized
- avalara— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300Q16CMW239SS315
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- New Hampshire State AGas victim2019-06-13
Avalara, Inc. notified the New Hampshire Attorney General of a data breach affecting 2 state residents. On May 22, 2019, a former employee of Compli, Inc. (now owned by Avalara) used valid credentials to access eCompli data. Exposed data included SSNs, driver's licenses, and PII. Notifications were sent on June 6, 2019.
- California State AGas victim2019-06-07
Avalara, Inc. disclosed a data breach involving the eCompli software application, acquired from Compli, Inc. On May 22, 2019, a former Compli employee notified Avalara of a vulnerability that allowed unauthorized access to personal information of certain individuals at Avalara's customers. The exposed data included names, SSNs, driver's license numbers, dates of birth, and employment history. The third party deleted the accessed data and certified it was not shared. Avalara removed the vulnerability, investigated the scope, and offered credit monitoring.
- Montana State AGas victim2019-06-02
Avalara, Inc. notified Montana residents of a data breach involving the eCompli software application. A former employee of a customer (and former Compli, Inc. employee) exploited a vulnerability in an eCompli code update on May 22, 2019, to access personal information. Exposed data included names, SSNs, driver's license numbers, and other PII. Avalara removed the vulnerability, investigated the scope, and offered credit monitoring.
- Massachusetts State AGas victim2019-05-22
Avalara Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-05-22. 9 Massachusetts residents were affected. The report records the breach type as electronic.