Late on Saturday, December 27, we were working through a possible account-security problem at Shutterstock. It was Christmas week, and the phone number I had for the communications team was not accepting calls.
The technical investigation was still underway. I wrote that I thought we were probably okay, but we did not have enough information to make a final statement.
I asked the group to do two things. First, prepare a message for any affected user accounts if we could isolate them. Second, get somebody from communications involved and decide whether we needed a public response. Shutterstock was already being described online as a hacked site.
At that point, Shutterstock had more than 1.2 million active paying users and more than 70,000 approved contributors. Customers had downloaded nearly 126 million items during the year. The collection held about 50 million images and more than two million video clips. Annual revenue was about $328 million.
The company had 512 full-time employees at year end. That was a substantial team, but it was small compared with the global customer and contributor base. An account issue could reach support and public channels in several countries before the right people in New York were connected.
That scale changed the response. A problem involving a small number of accounts could move through customer support, social media, and several time zones before most people at the company knew what was happening. The technical team could not handle the entire response alone.
We needed to find out which accounts, if any, were affected. That would determine who should receive a direct message. We also needed to start writing before every detail was known, because drafting and reviewing a customer message takes time.
A direct customer message and a public statement were different jobs. Someone whose account may have been affected needed to know what happened, what to do, and how to get help. A public statement needed to say what the company knew without exposing customer information or presenting an early theory as a settled fact.
Both depended on the technical investigation. The people looking at logs and account behavior had the facts. Communications and customer support knew how to turn those facts into something useful for customers. Legal judgment could also be necessary. We needed those groups talking early, not after the investigation was finished.
I did not want to send a general apology to the whole customer base before we knew who was involved. I wanted a specific message ready for the accounts connected to the event. That meant the work to isolate those accounts and the work to prepare the message had to happen at the same time.
Security incidents are different from a normal availability problem. If a service is down, restoring it is usually the first priority. With an account-security issue, normal product behavior does not tell you that the work is complete. You may need to preserve evidence, understand what information or access was exposed, identify customers, and avoid changing something that makes the cause harder to find.
The public description created another problem. If people outside the company were already calling Shutterstock hacked, there was pressure to respond quickly. A rushed response could be wrong. Waiting too long could leave customers with no useful information from us.
My email was short. I needed a working phone number for communications, a person who owned the public response, and a draft for affected users if the technical team could identify them. I ended by asking for thoughts because the investigation was still open and several people needed to make the decision together.
The source thread does not establish the final cause, the number of affected accounts, or the resolution. I am not filling those details in years later. What it does show is the response while we still did not know everything.
I thought we were probably okay. I still wanted the customer message started and the communications team on the phone.