HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Pathward, N.A.
bd_2ed03dab99fb0c73 · schema v1 · pii pii-v1
Full breach record for Pathward, N.A. →Pathward N.A. (via third-party Blackhawk Engagement Solutions) disclosed a data breach affecting MyPrepaidCenter.com users. Unauthorized access occurred between September 4-12, 2022, exposing names, emails, phone numbers, prepaid card numbers, expiration dates, and CVV codes. Pathward blocked affected cards, reissued new ones, and notified law enforcement. No specific count of affected individuals was disclosed in this filing.
California clockDiscovered Sep 11, 2022 → Notified Oct 31, 202250d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_865da679f25b0456Oregon State AGfiled 2022-11-01Verified
- bd_902bf95d52ccb8ccWashington State AGfiled 2022-11-01Verified
- bd_b10f529392d7c93eSouth Carolina State AGfiled 2022-11-01Verified
- bd_f88484b4b93eeb72Maine State AGfiled 2022-11-01Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_02fbbf8d67898111Delaware State AGfiled 2022-10-31(1d gap)Candidate
- bd_beae114d7254b7e1Montana State AGfiled 2022-10-31(1d gap)Verified
- bd_f12b26e9ca9edda3Delaware State AGfiled 2022-10-31(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-558767
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 1, 2022
- Raw hash
- ea3038a022b4328f3451c1f9a2cf6b8aba29764d01a6242867430d0ad42a7e81
Reporting entity
- Name
- Pathward, N.A.norm: pathward na
Victim entity
- Name
- Pathward, N.A.norm: pathward na
Incident
- Discovered
- Sep 11, 2022
- Materiality determined
- —
- Notification sent
- Oct 31, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 50d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 11, 2022→ Notified: Oct 31, 202250d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.