HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Advance America
bd_324083bfac683e39 · schema v1 · pii pii-v1
Full breach record for Advance America →NCAS of Delaware, LLC (d/b/a Advance America) reported a data security incident occurring on or around February 7, 2023, involving unauthorized access to corporate business records containing customer personal information. The company engaged third-party cybersecurity experts and law enforcement, implemented enhanced security measures, and offered one year of complimentary identity monitoring through Kroll to affected individuals.
Leak gap clock⏱ Leak >90d27 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 143 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_44194c52e6534a23Delaware State AGfiled 2023-08-15(1d gap)Verified
- bd_44ea510f141a9b17Vermont State AGfiled 2023-08-15(1d gap)Verified
- bd_fec8b5a3a4336c8eNew Hampshire State AGfiled 2023-08-21(7d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/08/ELN-18661-Purpose-Financial-2-Ad-CM-12m-r3prf.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2023
- Raw hash
- 85e3b958314cea66340a26ce3c8d3de650711b2267843fc89506e4cc3397c5d6
Reporting entity
- Name
- NCAS of Delaware, LLCnorm: ncas of delaware
Victim entity
- Name
- Advance Americanorm: advance america
- Domain
- advanceamerica.net
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported this incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 weeks(188 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.