MalwareRansomwareData ExfiltratedRansom DemandedData EncryptedPIIIDENTITY_BASICLowContained
AUTOPAY Direct, Inc.
bd_29d55959bdbcd925 · schema v1 · pii pii-v1
Full breach record for AUTOPAY Direct, Inc. →AUTOPAY Direct, Inc. disclosed a ransomware incident in February 2022 where a threat actor infiltrated its network, exfiltrated PII, and demanded ransom. The company did not pay, engaged forensic investigators, and notified law enforcement. Affected individuals were offered 12 months of credit monitoring.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_07d252a1f53fa056New Hampshire State AGfiled 2022-04-18(8d gap)Verified
- bd_27c3947e62aa6b16Washington State AGfiled 2022-04-14(12d gap)Verified by operator
- bd_2c0e299e2e7ca1b0South Carolina State AGfiled 2022-04-14(12d gap)Verified by operator
- bd_702f47d2350c448fMaine State AGfiled 2022-04-14(12d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 26d gap
- bd_d2c472e50e865641Montana State AGfiled 2022-03-31(26d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552867
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 26, 2022
- Raw hash
- 5026c0e511eb5e0348e02f46c06ca19e2f9a59e4b47cc0d7be20c5486ca48517
Reporting entity
- Name
- AUTOPAY Direct, Inc.norm: autopay direct
Victim entity
- Name
- AUTOPAY Direct, Inc.norm: autopay direct
Incident
- Discovered
- Feb 5, 2022
- Materiality determined
- Feb 5, 2022
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.