Breach report · Retail
Shutterfly Services Disrupted by Ransomware Attack Demanding Millions of Dollars as Ransom
A Conti ransomware attack on Shutterfly encrypted thousands of devices and exposed corporate financial data, legal documents and login credentials.
Exploit: Ransomware Company: Shutterfly Industry: Digital Image & Photography Services Sources: BleepingComputer
Shutterfly has been hit with a Conti ransomware attack that allegedly encrypted over 4,000 devices and 120 VMware ESXi servers. On the Conti leak site, they offer samples of stolen Shutterfly data including legal agreements, bank and merchant account info, login credentials for corporate services, spreadsheets, and customer information, including the last four digits of credit cards. Shutterfly said in a statement that their Shutterfly.com, Snapfish, TinyPrints, or Spoonflower sites were not affected by the attack. However, their corporate network, Lifetouch, BorrowLenses, and Groovebook experienced service disruptions.
Although there appears to be customer data involved in this incident including payment card data, that exposure has not been confirmed and no further information was available at press time.