Zola, Inc.
ent_be85487e13d53edccd045961
Disclosures
5
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,956
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Zola, Inc.
- Normalized
- zola— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- zola.com
Disclosure history (5)newest first
- Montana State AGas victim2022-07-05
Zola, Inc. notified users of a credential stuffing incident beginning May 20, 2022. Attackers used stolen credentials from other breaches to access Zola accounts. Compromised data included names, purchase history, shipping addresses, phone numbers, Zola store credit, and partial payment/bank details. Zola reset all user passwords and engaged external security firms.
- Indiana State AGas victim2022-07-05
Zola, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-05-20 and was reported on 2022-07-05. 37 Indiana residents were affected. 2,956 individuals affected in total.
- Massachusetts State AGas victim2022-07-05
Zola, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-07-05. 107 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-07-04
Zola, Inc. experienced a credential stuffing attack from May 20, 2022, to May 24, 2022, discovering the incident on May 21, 2022. The breach affected 2,956 individuals in total, including 6 residents of Maine. The company notified the affected Maine residents in writing on July 5, 2022.
- Maine State AGas victim2022-06-21
Zola, Inc. experienced a credential stuffing incident on May 21, 2022, which was also the date of discovery. The breach affected one Maine resident who was notified on May 23, 2022.