CAMBRIDGE MERCANTILE CORP. (U.S.A.)
bd_30c60ad8da5fb687 · schema v1 · pii pii-v2
Full breach record for CAMBRIDGE MERCANTILE CORP. (U.S.A.) →Cambridge Mercantile Corp. (U.S.A.) (Corpay) notified individuals of a data security incident where an unauthorized third party accessed personal information including names and contact details. The investigation was substantially completed on August 28, 2026. No passwords, credentials, or financial funds were compromised. The company engaged third-party experts, enhanced security safeguards, and provided identity monitoring services via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Sep 1, 2026
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- California State AGbd_e673f27ac5ae3e2f2026-09-14 · +13dCandidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Sep 1 (MA), last Sep 14 (CA) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.