Gyft, Inc.
ent_42d43b1980a4a56dc44e6f0a
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
392,773
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Gyft, Inc.
- Normalized
- gyft— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Massachusetts State AGas victim2016-02-09
Gyft, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-02-09. 8,112 Massachusetts residents were affected. The report records the breach type as electronic.
- Hawaii State AGas victim2016-02-09
Gyft, Inc. notified the Hawaii Office of Consumer Protection of a security breach involving unauthorized access to its cloud providers between October 3 and December 18, 2015. The attacker used valid Gyft credentials to access user data including names, addresses, DOBs, emails, and gift card numbers. Gyft discovered the incident on December 3, 2015, and began notifying users in February 2016.
- Oregon State AGas victim2016-02-05
Gyft, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2016-02-05. The breach occurred during 10/3/2015 - 12/18/2015. 392,773 individuals were affected. Notice was sent on 2/5/2016.
- Montana State AGas victim2016-02-05
Gyft, Inc. notified Montana residents that an unknown party gained unauthorized access to cloud providers between Oct 3 and Dec 18, 2015. Access involved compromised user credentials, exposing names, addresses, DOBs, phone numbers, emails, and gift card numbers. Gyft forced password resets and reset Coinbase tokens.
- California State AGas victim2016-02-05
Gyft, Inc. reported that an unknown party accessed without authorization two cloud providers used by Gyft from October 3 through December 18, 2015. The attacker could view or download user information including names, addresses, dates of birth, phone numbers, email addresses, gift card numbers, and potentially login credentials for users active between March 19 and December 4, 2015. No credit card numbers were compromised. Gyft forced password resets and reset Coinbase tokens for affected users.
- New Hampshire State AGas victim2016-02-05
Gyft, Inc. notified New Hampshire AG of a security breach involving unauthorized access to two cloud providers between Oct 3 and Dec 18, 2015. Access exposed user PII (names, addresses, DOB, phone, email) and gift card numbers. Login credentials were also compromised for users active between March and Dec 2015. Gyft is notifying 1,184 NH residents and forcing password resets.
- Washington State AGas victim2016-02-04
Gyft, Inc. notified Washington AG of unauthorized access to two cloud providers between Oct 3 and Dec 18, 2015. Access exposed names, addresses, DOBs, emails, phone numbers, gift card numbers, and login credentials for 9,042 Washington residents. Notifications began Feb 5, 2016. Gyft forced password resets and reset Coinbase tokens. Investigation ongoing.