HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Pathward, N.A.
bd_02fbbf8d67898111 · schema v1 · pii pii-v1
Full breach record for Pathward, N.A. →Blackhawk Engagement Solutions, a third-party provider for Pathward N.A., notified affected individuals of a data breach involving the MyPrepaidCenter.com website. Unauthorized access occurred between September 4 and 12, 2022, exposing names, emails, phone numbers, prepaid card numbers, expiration dates, and CVV codes. Blackhawk contained the incident, blocked and reissued cards, and reported to law enforcement. This is a sample notification letter filed with the Delaware Attorney General.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_beae114d7254b7e1Montana State AGfiled 2022-10-31Verified
- bd_f12b26e9ca9edda3Delaware State AGfiled 2022-10-31Verified
- bd_2ed03dab99fb0c73California State AGfiled 2022-11-01(1d gap)Candidate
- bd_865da679f25b0456Oregon State AGfiled 2022-11-01(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_902bf95d52ccb8ccWashington State AGfiled 2022-11-01(1d gap)Verified
- bd_b10f529392d7c93eSouth Carolina State AGfiled 2022-11-01(1d gap)Verified
- bd_f88484b4b93eeb72Maine State AGfiled 2022-11-01(1d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/11/Pathward-N.A-Data-Breach-Sample-Letter-Non-MA-10.31.2022.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 31, 2022
- Raw hash
- 2a99bcf4194dee70dbb40c7715cd5212b362827ff030e028fcbd1a36198f3561
Reporting entity
- Name
- Blackhawknorm: blackhawk
- Domain
- blackhawk.com
Victim entity
- Name
- Pathward, N.A.norm: pathward na
- Industry
- financial_services
Incident
- Discovered
- Sep 11, 2022
- Materiality determined
- —
- Notification sent
- Oct 31, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to law enforcement
- Third party
- via Blackhawk Engagement Solutions
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.