Animoto Inc. notified the California AG of unauthorized access to user data on July 10, 2018. The incident involved suspicious queries against the user database, potentially exposing names, emails, hashed/salted passwords, geolocation, gender, and dates of birth. Animoto stopped the queries, engaged third-party experts, reset passwords, and reduced system access. No payment card data was accessed. Notices were sent starting August 16, 2018.