HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
UNIVERSAL LENDERS, LLC
bd_28bfcd45a014e0ef · schema v1 · pii pii-v1
Full breach record for UNIVERSAL LENDERS, LLC →Universal Lenders, LLC reported a data security incident to the Maryland Attorney General on January 21, 2025. Unauthorized access occurred on November 7, 2024, and was detected on December 5, 2024. The breach affected approximately 119 Maryland residents, exposing Social Security numbers, financial account numbers, and driver's license information. Universal Lenders engaged independent cybersecurity experts, notified affected individuals, and offered complimentary identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed119 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376217.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 3b9bd601dad57c82178146e62342a846e09d8bbec7d0db33950c6a891b8efb7b
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- UNIVERSAL LENDERS, LLCnorm: universal lenders
Incident
- Discovered
- Dec 5, 2024
- Materiality determined
- —
- Notification sent
- Jan 21, 2025
- Affected individuals
- 119
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 49 weeks(343 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.