Oregon Zoo
ent_a2f197dfaaa9896cc932d973
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
117,815
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Oregon Zoo
- Normalized
- oregon zoo— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- New Hampshire State AGas victim2024-08-16
Oregon Zoo notified New Hampshire AG of a data security event involving unauthorized access to personal information, including SSNs and payment card data. The zoo notified federal law enforcement, engaged CyberScout for credit monitoring, and is reviewing policies. Approximately 129 Rhode Island residents were identified as potentially impacted.
- Massachusetts State AGas victim2024-08-16
Oregon Zoo reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-08-16. 309 Massachusetts residents were affected.
- Indiana State AGas victim2024-08-16
Oregon Zoo reported a data breach to the Indiana Attorney General. The breach occurred on 2023-12-20 and was reported on 2024-08-16. 200 Indiana residents were affected. 117,815 individuals affected in total.
- California State AGas victim2024-08-16
Oregon Zoo notified customers of a data breach involving payment card information. On June 26, 2024, the zoo detected suspicious activity in its online ticketing service. An investigation revealed that an unauthorized actor redirected transactions from a third-party payment vendor, potentially accessing payment card data from December 20, 2023, to June 26, 2024. Affected data includes names, payment card numbers, CVVs, and expiration dates. The zoo decommissioned the site, notified law enforcement, and is offering 12 months of credit monitoring.
- Maine State AGas victim2024-08-16
Oregon Zoo reported a data breach affecting 117,815 individuals. Unauthorized actors redirected transactions via a third-party ticketing vendor, accessing payment card data (name, number, CVV, expiration) from Dec 20, 2023, to June 26, 2024. The incident was discovered on June 26, 2024. Notices were sent on Aug 16, 2024. The site was decommissioned, rebuilt securely, and credit monitoring was offered.
- Oregon State AGas victim2024-08-16
Oregon Zoo reported a data breach to the Oregon Attorney General. The breach was reported on 2024-08-16. 117,815 individuals were affected.
- Montana State AGas victim2024-08-16
Oregon Zoo notified Montana AG of a security incident involving its online ticketing service. An unauthorized actor redirected transactions via a third-party vendor, potentially accessing payment card info (name, number, CVV, expiration) from Dec 20, 2023, to June 26, 2024. The site was decommissioned, rebuilt, and law enforcement notified. Credit monitoring offered.
- Washington State AGas victim2024-08-16
Oregon Zoo notified Washington residents of a cyberattack involving its third-party online ticketing vendor. Unauthorized actors redirected transactions, potentially accessing payment card data (name, number, CVV, expiration) from Dec 20, 2023, to June 26, 2024. 22,901 Washington residents were notified starting Aug 16, 2024. The site was decommissioned and rebuilt; credit monitoring was offered.
- Vermont State AGas victim2024-08-15
Oregon Zoo notified consumers of a security incident involving its online ticketing service. An unauthorized actor redirected transactions via a third-party vendor, potentially obtaining payment card data (name, number, CVV, expiration) from Dec 20, 2023 to June 26, 2024. The Zoo decommissioned the site, rebuilt it securely, notified law enforcement, and offered 12 months of credit monitoring. Approximately 129 Rhode Island residents were explicitly identified as impacted.