HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Paysafe Group Holdings Limitedd
bd_1c3042be6747728b · schema v1 · pii pii-v1
Full breach record for Paysafe Group Holdings Limitedd →Paysafe Group Holdings Limited reported a data breach affecting a legacy website used by its Merchant Services division (including iPayment and CHI Payments). Unauthorized actors accessed the site between May 13, 2018, and November 24, 2020, potentially exposing names, contact details, Social Security numbers, and bank account information. Paysafe engaged forensic experts, notified law enforcement, and closed the website. Affected individuals received two years of free credit monitoring via Kroll.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1151afe21cdd47ffWashington State AGfiled 2020-12-16Verified
- bd_a7e7764a6bda2706South Carolina State AGfiled 2020-12-16Verified
- bd_6a289d8c42bb094cMaine State AGfiled 2021-01-12(27d gap)Verified
- bd_8e5980705d10b8f5Oregon State AGfiled 2021-01-19(34d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197247
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2020
- Raw hash
- 7dcdb7bb83036ff9f9619fe0ae945227cb8a86e02cf4f7e4627113b4e5fb6307
Reporting entity
- Name
- Paysafe Group Holdings Limiteddnorm: paysafe group holdings limitedd
Victim entity
- Name
- Paysafe Group Holdings Limiteddnorm: paysafe group holdings limitedd
Incident
- Discovered
- Nov 6, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.