Menu
Browse

Cyber Incident Victim: Kickstarter

Date:

Feb 2014

Location:

United States of America

Summary

A crowdfunding platform suffered a security breach resulting in unauthorized access to personal user data, including usernames, email addresses, mailing addresses, phone numbers, and encrypted passwords. Law enforcement notified the company of the incident, prompting immediate closure of the breach and implementation of enhanced security measures; no credit card information was compromised, and investigators identified only two instances of unauthorized account access. The organization publicly apologized for the incident, confirmed ongoing collaboration with authorities, and committed to further strengthening its security infrastructure to prevent future occurrences.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On February 16, 2014, Kickstarter publicly disclosed a security breach after law enforcement officials alerted the company to unauthorized access on Wednesday of that week. The crowdfunding platform confirmed that attackers had obtained personal customer data, including usernames, email addresses, mailing addresses, phone numbers, and encrypted passwords. Kickstarter immediately closed the security breach upon discovery and initiated efforts to strengthen its security infrastructure. The company emailed users on Saturday night urging password changes, though it emphasized no credit card data was compromised in the incident. According to Kickstarter’s investigation, only two instances of unauthorized account access occurred as a result of the breach. The company’s blog post stated it had launched in 2009 and accumulated over 5.6 million user accounts by the time of the intrusion.

Cyber Incident Image

Kickstarter characterized the breach as “frustrating and upsetting” in its public statement, apologizing to users while detailing ongoing security enhancements. The organization collaborated with law enforcement agencies to investigate the incident and implemented procedural and technical improvements to prevent recurrence. No specific details about the attackers’ methods or the duration of system access were disclosed. The compromised encrypted passwords raised concerns about potential decryption attempts, though Kickstarter did not specify the encryption standards used. Impacts extended to all users whose personal information was exposed, though financial data remained unaffected. The company committed to continuous security upgrades in subsequent months while maintaining its operational services throughout the response period.

Sources
Sources available to members
1 source