Zazzle Inc.
ent_afd243101db063f222e5101f
Disclosures
2
State AG · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Zazzle Inc.
- Normalized
- zazzle— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- California State AGas victim2017-08-25
In July 2017, Zazzle detected a brute force attack where unauthorized parties used credentials obtained from other breaches to attempt logins to Zazzle accounts. Usernames (email addresses) and passwords were potentially compromised. Zazzle reset affected passwords and implemented CAPTCHA to prevent automated logins.
- California State AGas victim2016-09-21
Zazzle Inc. notified California residents that unauthorized login attempts were detected on user accounts. The company determined that the usernames and passwords used in the incident were obtained from a data breach of another website (credential stuffing). Zazzle reset affected passwords and prompted users to create new ones. The breach dates listed on the state filing are August 15-22, 2016.