HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Nelnet Servicing, LLC Class Action Settlement
bd_0c865b6ff7a99401 · schema v1 · pii pii-v1
Full breach record for Nelnet Servicing, LLC Class Action Settlement →Edfinancial Services, LLC reported a data breach involving its third-party provider, Nelnet Servicing, LLC. The incident occurred between June 1, 2022, and July 22, 2022, when an unknown party accessed student loan account registration information, including names, addresses, emails, phone numbers, and Social Security numbers. Nelnet discovered the vulnerability on July 21, 2022, secured systems, and engaged forensic experts. Edfinancial notified the U.S. Department of Education and law enforcement, and offered 24 months of credit monitoring to affected individuals.
California clockDiscovered Jul 21, 2022 → Notified Aug 26, 202236d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e7ee505dd1257733Delaware State AGfiled 2022-08-26Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556689
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 26, 2022
- Raw hash
- d8da5e8efbb7a4a654c4684e870c8b3cc3ee2be5faa6b8da5e2e6c139449af0c
Reporting entity
- Name
- Edfinancial Services, LLCnorm: edfinancial services
Victim entity
- Name
- Nelnet Servicing, LLC Class Action Settlementnorm: nelnet servicing llc class action settlement
- Domain
- nelnetsettlement.com
Incident
- Discovered
- Jul 21, 2022
- Materiality determined
- —
- Notification sent
- Aug 26, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the U.S. Department of EducationNotified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 36d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 21, 2022→ Notified: Aug 26, 202236d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.