HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPIIMediumContained
MONEYGRAM PAYMENT SYSTEMS, INC.
bd_2268c0d1e1ce0cc7 · schema v1 · pii pii-v1
Full breach record for MONEYGRAM PAYMENT SYSTEMS, INC. →MoneyGram Payment Systems, Inc. disclosed a cybersecurity incident affecting consumer and employee data. An unauthorized third party accessed systems between September 20-22, 2024, with discovery on September 27, 2024. Impacted data included names, contact info, DOB, SSNs, driver's licenses, and bank account numbers. MoneyGram took systems offline, engaged forensic experts, coordinated with law enforcement, and offered two years of free credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_824b0799a7eeea49Indiana State AGfiled 2024-10-07Verified
- bd_af72316c8420b246Washington State AGfiled 2024-10-07Verified
- bd_fe9c21d24d34ef98Montana State AGfiled 2024-10-07Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/11/MoneyGram-Enclosures-2-10-07-24.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 7, 2024
- Raw hash
- 5c7c36c0c4d13bf78aa1af03f19a9e6a4d8aa5bd589fb8f192a5baad61dc0b58
Reporting entity
- Name
- MONEYGRAM PAYMENT SYSTEMS, INC.norm: moneygram payment
- Domain
- moneygram.com
Victim entity
- Name
- MONEYGRAM PAYMENT SYSTEMS, INC.norm: moneygram payment
- Domain
- moneygram.com
Incident
- Discovered
- Sep 27, 2024
- Materiality determined
- —
- Notification sent
- Oct 7, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- coordinating with law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 days(10 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.