DisclosureLens
AccidentalFinancial ServicesProfessional ServicesFinanceMisdeliveryCustomer Data InvolvedSupply Chain (3P Vendor)Identity (basic)Government IDMediumResolved

AccessLex Institute

bd_252d53a7098baa46 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 28, 2018

Filed

Apr 18, 2018

To disclose

21 days

Affected

Not disclosed

Confidence

65%
Full breach record for AccessLex Institute3 incidents on file

AccessLex Institute d/b/a Access Group notified the California Attorney General that a vendor inadvertently sent loan files containing names, driver's license numbers, and Social Security numbers to an unauthorized business on March 23, 2018. The company learned of the incident on March 28, 2018. The unauthorized recipient confirmed deletion of the files. AccessLex is offering one year of identity protection services.

Incident timeline

undetected · 5 days
discovery → filing · 21 days

Mar 23, 2018

Begins

Mar 28, 2018

Discovered

Apr 18, 2018

Filed

vs. sector median

5 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.