Recommended Free Tools
Shutterfly said a ransomware attack in December 2021 disrupted manufacturing, parts of several business units and some corporate systems. Its initial notice said Shutterfly.com, Snapfish, TinyPrints and Spoonflower were not affected. A later breach notification reported that attackers accessed employee information, including potentially salary and leave-related records.
What happened in the Shutterfly ransomware attack?
In a statement dated Dec. 26, 2021, Shutterfly said it had “recently experienced a ransomware attack on parts of our network.” The company said portions of its Lifetouch and BorrowLenses businesses, Groovebook, manufacturing and some corporate systems were experiencing interruptions. It said it had engaged outside cybersecurity experts and informed law enforcement while assessing the incident and potentially affected data. Shutterfly’s Dec. 26 statement
SecurityWeek’s Dec. 28 report likewise identified manufacturing and corporate systems among the affected areas. Contemporary reporting attributed the attack to the Conti ransomware group, but Shutterfly’s initial statement did not name Conti. SecurityWeek’s report
Which Shutterfly services and operations were affected?
| Service or operation | What Shutterfly said |
|---|---|
| Manufacturing | Experiencing interruptions, according to the Dec. 26, 2021 statement. Shutterfly |
| Lifetouch and BorrowLenses | Portions of each business were experiencing interruptions. Shutterfly |
| Groovebook | Experiencing interruptions. Shutterfly |
| Corporate systems | Some systems were affected; SecurityWeek also reported corporate systems as affected. Shutterfly SecurityWeek |
| Shutterfly.com, Snapfish, TinyPrints and Spoonflower | Shutterfly said these sites were not impacted by the incident in its initial notice. Shutterfly |
Was customer or employee data stolen?
A later breach notification, reported by BleepingComputer, said attackers accessed Shutterfly’s network around Dec. 3, 2021; the company discovered the incident on Dec. 13, and ransomware was deployed during the compromise. The notice said accessed employee information could include names, salary and compensation information, and records related to FMLA leave or workers’ compensation claims. The report does not establish that every listed category was accessed for every affected employee. BleepingComputer’s report on the notification
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
In its initial statement, Shutterfly said it did not store customers’ credit-card or financial-account numbers, or Social Security numbers, for the listed services, and said those categories were not impacted in the incident. It also said its assessment of potentially affected data was ongoing, so that initial statement should not be read as a complete final account of all data potentially involved. Shutterfly’s statement
How many devices did Conti encrypt?
BleepingComputer reported a source’s claim that Conti encrypted more than 4,000 devices and 120 VMware ESXi servers. Those figures were attributed to a source, not published by Shutterfly as an official count or described as independently verified. BleepingComputer’s report on the figures
Rank #2
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
What is not publicly established?
The available reporting does not establish a final restoration date for all manufacturing systems, whether a ransom was paid, the total financial loss, or a definitive complete count of affected records. These points remain unknown based on the cited accounts.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How this differs from Shutterfly’s 2023 MOVEit disclosure
The 2023 MOVEit vulnerability disclosure was a separate incident involving Shutterfly Business Solutions, not the 2021 ransomware attack. BleepingComputer reported that after investigating the MOVEit vulnerability, Shutterfly found no indication that specified consumer or employee data was affected. The two events should not be combined when describing the 2021 incident. BleepingComputer’s MOVEit report
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Best Value
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Rank #4
- SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
- Capture ATP with RTDMI for Enterprise: Defend against zero-day exploits and ransomware using multi-engine cloud sandboxing and advanced memory inspection.
- Full Threat Protection Stack: Includes Gateway AV, Intrusion Prevention, Anti-Spyware, Application Control, and Content Filtering for layered defense.
- 24x7 Global Support & Firmware Updates: Keep your firewall protected and operational with continuous technical assistance and critical firmware upgrades.
- Application Intelligence & Network Control: Identify and control network activity with deep traffic analytics and reporting features.
Rank #3
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




