Menu
Browse

Cyber Incident Victim: Docsketch

Date:

Aug 2020

Location:

United States of America

Summary

An electronic document-signing service experienced a security breach where an unauthorized party accessed a database snapshot containing user-submitted form data, including names, signatures, personal information, and payment card details, though document files themselves remained uncompromised. The exposed database also held login credentials with salted and hashed passwords, alongside user contact lists. The incident occurred during a summer month, prompting the company to secure its systems, notify affected customers, and implement infrastructure updates while advising users to take protective measures if they entered sensitive data. Ongoing security enhancements were prioritized following the intrusion.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early August 2020, an unauthorized third party gained access to a copy of Docsketch's database containing a snapshot of the service as of July 9, 2020. The compromised database included contact information, form fields related to documents filled out by users and recipients, and login credentials. While the documents themselves were not accessed, the exposed form fields contained sensitive data entered by users during document completion, such as names, signatures, personal identifiers, and payment card details where applicable. The database also stored user contact lists comprising individuals invited to complete documents. Password strings were protected with salting and hashing techniques, though the company did not disclose specifics about the cryptographic strength or implementation details of these security measures. Docsketch founder Ruben Gamez confirmed the breach via customer notifications, clarifying that the intrusion occurred despite the documents remaining inaccessible to attackers.

Cyber Incident Image

Following the August intrusion, Docsketch implemented system security enhancements and infrastructure updates. The company initiated customer notifications specifically targeting users who entered personal or financial information in documents, providing them with additional protective measures. Gamez stated that resolving the breach remained the organization's top priority, with plans for continued security and infrastructure improvements underway. The incident impacted an unspecified number of users given Docsketch's status among the Alexa Top 25,000 most visited websites at the time. Exposed data primarily consisted of metadata and form inputs rather than complete documents, though this still included sensitive elements like partial payment information and personally identifiable details from document fields. No evidence suggested ongoing unauthorized access after containment measures were applied.

Sources
Sources available to members
1 source