Epik Holdings, Inc.
ent_7548a45444e736e99e07df91
Disclosures
8
State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
110,000
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Epik Holdings, Inc.
- Normalized
- epik holdings— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- epik.com
Disclosure history (8)newest first
- Oregon State AGas victim2021-09-22
Epik Holdings, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-09-22. The breach occurred during 9/13/2021. The breach was discovered on 9/15/2021. 110,000 individuals were affected. Notice was sent on 9/20/2021.
- Washington State AGas victim2021-09-22
Epik Holdings, Inc. disclosed unauthorized access to domain-side service account backups on or before September 13, 2021. The breach affected 2,040 Washington residents, exposing names, addresses, usernames, passwords, and credit card data for a subset. Epik engaged forensic partners, secured services, and notified consumers by September 20, 2021.
- Maine State AGas victim2021-09-22
Epik Holdings, Inc. reported an external system breach (hacking) that occurred on September 13, 2021, and was discovered on September 15, 2021. The breach affected 190 Maine residents, part of a total of 110,000 individuals. The compromised information included names in combination with financial account numbers or credit/debit card numbers and their security codes. Epik Holdings provided electronic notification to the affected consumers on September 20, 2021, and offered two years of identity theft protection services through Experian.
- Massachusetts State AGas victim2021-09-22
Epik Holdings, Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-09-22. 1,500 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2021-09-22
Epik Holdings, Inc. disclosed that unauthorized third parties accessed a backup copy of domain-side service accounts on or before September 13, 2021. The breach affected approximately 300 New Hampshire residents, exposing names, addresses, emails, usernames, passwords, phone numbers, transaction history, and for some, credit card information. The investigation is ongoing. Epik has secured access, applied additional security measures, and is offering free credit monitoring.
- California State AGas victim2021-09-20
Epik Holdings, Inc. confirmed a data intrusion on September 15, 2021, involving unauthorized access to a backup copy of domain-side service accounts on or before September 13, 2021. Affected data includes names, addresses, emails, usernames, passwords, phone numbers, VAT numbers, transaction history, domain ownership, and for some users, credit card information. Epik retained cybersecurity partners, secured services, and offered credit monitoring.
- Montana State AGas victim2021-09-20
Epik Holdings, Inc. issued a supplemental notice regarding a data intrusion confirmed on September 15, 2021. Unauthorized parties accessed a backup of domain-side service accounts on or before September 13, 2021. Data obtained included names, addresses, emails, usernames, passwords, and credit card info for a subset. Epik engaged forensic partners, secured services, and offered credit monitoring.
- Indiana State AGas victim2021-09-20
Epik Holdings, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-09-13 and was reported on 2021-09-20. 727 Indiana residents were affected. 110,000 individuals affected in total.