HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
1ST FRANKLIN FINANCIAL CORPORATION
bd_3fa3cf4006932edb · schema v1 · pii pii-v1
Full breach record for 1ST FRANKLIN FINANCIAL CORPORATION →1st Franklin Financial Corporation reported a security incident occurring on November 17-18, 2022, where an unauthorized third party accessed and potentially exfiltrated data. Affected data includes names, SSNs, and bank account/routing numbers. The company blocked access, changed passwords, engaged forensic experts, and offered credit monitoring. No specific count of affected individuals was disclosed in the notice sample.
California clockDiscovered Nov 17, 2022 → Notified Feb 14, 202389d ✗ CA 60-day late18 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0f301abc01d259d1Montana State AGfiled 2023-03-02(21d gap)Verified by operator
- bd_78421a87f880eedcVermont State AGfiled 2023-03-02(21d gap)Verified
- bd_7d2d18c82fcc9cb1New Hampshire State AGfiled 2023-03-02(21d gap)Verified
- bd_9eb0df3dc0ec2cb2Maine State AGfiled 2023-01-18(64d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564676
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 23, 2023
- Raw hash
- 342099e1ed091f7c5ba4001573b3ff720dc9b32aefbc0d9412150937b9f71529
Reporting entity
- Name
- 1ST FRANKLIN FINANCIAL CORPORATIONnorm: 1st franklin financial
Victim entity
- Name
- 1ST FRANKLIN FINANCIAL CORPORATIONnorm: 1st franklin financial
Incident
- Discovered
- Nov 17, 2022
- Materiality determined
- —
- Notification sent
- Feb 14, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- CA 60-day late · 89d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 17, 2022→ Notified: Feb 14, 202389d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.