HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
LCS
bd_325c9c186e879881 · schema v1 · pii pii-v1
Full breach record for LCS →LCS Financial Services, a nationwide debt collection agency, notified individuals of a cybersecurity incident occurring on February 24, 2023, discovered on February 25, 2023. The breach involved unauthorized access to systems, potentially exposing names and government identifiers (SSN, driver's license). LCS engaged independent cybersecurity experts, reported the incident to the FBI, and offered complimentary credit monitoring and identity theft protection services through IDX. No evidence of actual misuse was found.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_4d65c3817dcd07ecNew Hampshire State AGfiled 2023-10-24Verified
- bd_67d6fd7c7ebc7984California State AGfiled 2023-10-24Verified
- bd_9590de5068b55cb1Vermont State AGfiled 2023-10-24Verified
- bd_ba4a13b35dcea53bHHS OCRfiled 2023-10-24Verified
Show 6 more filings ↓Show fewer ↑up to 32d gap
- bd_1dca0a5fdc12edfbVermont State AGfiled 2023-10-05(19d gap)Verified
- bd_3d0bf692d70d11b1Delaware State AGfiled 2023-10-05(19d gap)Candidate
- bd_76f339ccce59c020Delaware State AGfiled 2023-10-05(19d gap)Candidate
- bd_c23ff9723b2552b0California State AGfiled 2023-10-05(19d gap)Candidate
- bd_354d6ed0cdc83cefVermont State AGfiled 2023-09-22(32d gap)Verified
- bd_5db881e7e0b4d1a7California State AGfiled 2023-09-22(32d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/11/LCS-Financial.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 24, 2023
- Raw hash
- e9167f8f88b3c3b5e4c0a4dca9e717e1d30c7621a7882f5ed00614dcd48041f4
Reporting entity
- Name
- LCSnorm: lcs
- Domain
- lcsfin.com
Victim entity
- Name
- LCSnorm: lcs
- Domain
- lcsfin.com
Incident
- Discovered
- Feb 25, 2023
- Materiality determined
- —
- Notification sent
- Oct 24, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- reported the incident to the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 34 weeks(241 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.