Divvy Up, Inc.
ent_5ea6f1a1bd3ec9ffd2a525c1
Disclosures
17
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
46,958
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Divvy Up, Inc.
- Normalized
- divvy up— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (17)newest first
- New Hampshire State AGas victim2021-08-02
Divvy Up, Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving its website hosting provider. Malware was downloaded to the hosted website, allowing an unknown third party to access payment transactions between May 10, 2021, and June 18, 2021. Affected data included customer names, addresses, and payment card details (number, CVC, expiration). 152 New Hampshire residents were affected. Divvy Up engaged a security service, upgraded protocols, and restricted payments to PayPal during remediation.
- Indiana State AGas victim2021-07-30
Divvy Up, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-05-10 and was reported on 2021-07-30. 641 Indiana residents were affected. 38,505 individuals affected in total.
- Massachusetts State AGas victim2021-07-30
Divvy Up, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-07-30. 996 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2021-07-30
Divvy Up, Inc. disclosed that malware downloaded to its hosted website via a compromised hosting provider allowed unauthorized access to payment transaction data between May 10, 2020, and June 18, 2021. Affected data included names, addresses, and payment card details (number, CVC, expiration). The company contained the incident, removed malware, upgraded security protocols, and temporarily restricted payments to PayPal.
- Maine State AGas victim2021-07-30
Divvy Up, Inc. reported an external system breach that occurred between May 10, 2021, and June 18, 2021. The breach was discovered on June 18, 2021. The compromised information includes names or other personal identifiers in combination with financial account numbers or credit/debit card numbers along with their security codes, access codes, passwords, or PINs. A total of 96 Maine residents were affected. Notification letters were sent to the affected individuals on July 30, 2021.
- Montana State AGas victim2021-07-30
Divvy Up, Inc. notified Montana residents of a data breach involving its website hosting company. Malware was downloaded to the hosted website, compromising payment transactions between May 10, 2020, and June 18, 2021. Affected data included names, addresses, and payment card details (number, CVC, expiration). Divvy Up engaged forensic services, removed malware, upgraded security, and restricted payments to PayPal.
- Maine State AGas victim2021-05-04
Divvy Up, Inc. reported an external system breach (hacking) occurring between December 1, 2020, and March 8, 2021, discovered on March 10, 2021. The incident affected 46,958 individuals, including 185 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). Written notifications were sent on May 3, 2021. No identity theft protection services were offered.
- Massachusetts State AGas victim2021-05-04
Divvy Up, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-05-04. 1,614 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2021-05-03
Divvy Up, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-12-01 and was reported on 2021-05-03. 809 Indiana residents were affected. 46,958 individuals affected in total.
- Oregon State AGas victim2021-05-03
Divvy Up, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-05-03. The breach occurred during 12/1/2020 - 3/8/2021. The breach was discovered on 3/10/2021. 46,958 individuals were affected. Notice was sent on 5/3/2021.
- Montana State AGas victim2021-05-03
Divvy Up, Inc. notified Montana residents that its website hosting company's network was compromised, allowing malware to be downloaded to the hosted website. The breach affected payment card information (number, CVC, expiration) for transactions made between December 1, 2020, and March 8, 2021. Divvy Up discovered the incident on March 10, 2021, engaged a certified expert for vulnerability scanning, and ensured the hosting provider removed the malware and upgraded security protocols.
- California State AGas victim2021-05-03
Divvy Up, Inc. notified customers that malware was downloaded to their hosted website via a compromise of their website hosting company's network security between December 1, 2020, and March 8, 2021. The incident, discovered on March 10, 2021, potentially exposed names, addresses, and payment card information (including card numbers, CVC codes, and expiration dates) for transactions made through the site. PayPal transactions were unaffected. The company engaged a third-party expert to confirm the removal of the vulnerability and advised customers to monitor their accounts.
- Washington State AGas victim2021-05-03
Divvy Up, Inc. notified the Washington AG of a cyberattack affecting 1,137 WA residents. Malware on the hosted website allowed unauthorized access to payment transactions (names, addresses, card numbers, CVC, expiration) between Dec 1, 2020 and Mar 8, 2021. Discovered Mar 10, 2021. Notifications mailed May 3, 2021.
- New Hampshire State AGas victim2021-05-03
DivvyUp, Inc. notified the NH AG of a data event affecting 229 NH residents. Malware on DivvyUp's hosted website allowed unauthorized access to payment transactions (Dec 1, 2020 - Mar 8, 2021), exposing names, addresses, and full payment card details. Discovered March 10, 2021. Notifications mailed May 3, 2021.
- Washington State AGas victim2021-05-03
Divvy Up, Inc. notified Washington AG of a cyberattack where malware on its hosted website allowed unauthorized access to payment data (names, addresses, card numbers, CVC, expiration) for 1,137 WA residents. Access occurred Dec 1, 2020–Mar 8, 2021; discovered Mar 10, 2021. Notifications mailed May 3, 2021.
- Illinois State AGas victim2021-01-01
DIVVY UP, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-150). The register records the breach as discovered on March 10, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2021-01-01
DIVVY UP, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-305). The register records the breach as discovered on March 10, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.