MalwareRansomwareData EncryptedData ExfiltratedIDENTITY_GOVERNMENTPIIMediumContained
RPM Receivables Performance Management
bd_29434f5b2c74747d · schema v1 · pii pii-v1
Full breach record for RPM Receivables Performance Management →Receivables Performance Management LLC (RPM) disclosed a ransomware incident affecting its server infrastructure. First access occurred April 8, 2021, with ransomware deployment on May 12, 2021. RPM disconnected equipment, rebuilt servers, and retained forensic investigators. Personal information, including Social Security numbers, was potentially accessed. RPM offered TransUnion credit monitoring to affected individuals.
California clockDiscovered May 12, 2021 → Notified May 12, 2022365d ✗ CA 60-day late19 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_c0271b51208c2f7fDelaware State AGfiled 2022-11-21Candidate
- bd_ad14f16fc621026cDelaware State AGfiled 2022-10-02(50d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-559383
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2022
- Raw hash
- 50ad57fcf3cea915f49d61ca8aaa1ddb85e5ef2eee7c2f4cd8106c9110bd6370
Reporting entity
- Name
- RPM Receivables Performance Managementnorm: rpm receivables performance management
- Domain
- receivablesperformance.com
Victim entity
- Name
- RPM Receivables Performance Managementnorm: rpm receivables performance management
- Domain
- receivablesperformance.com
Incident
- Discovered
- May 12, 2021
- Materiality determined
- —
- Notification sent
- May 12, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 19 months(558 days from discovery to filing)
- Compliance flags
- CA 60-day late · 365d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 12, 2021→ Notified: May 12, 2022365d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.