HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTBIOMETRICMediumActive
BYTE FEDERAL, INC.
bd_43871576fda33170 · schema v1 · pii pii-v1
Full breach record for BYTE FEDERAL, INC. →Byte Federal Inc. disclosed a security breach discovered on November 18, 2024, where an unauthorized actor exploited a vulnerability in third-party software to access a server. The breach occurred on September 30, 2024. Affected data includes names, birthdates, addresses, phone numbers, emails, government-issued IDs, SSNs, transaction activity, and photographs. The company shut down its platform, isolated the attacker, reset customer accounts, and engaged forensic investigators. The investigation is ongoing.
California clockDiscovered Nov 18, 2024 → Notified Dec 1, 202413d ✓ CA 60-day OK23 days discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0db76d11ece12d45Montana State AGfiled 2024-12-11Candidate
- bd_8379555c684c474bMaine State AGfiled 2024-12-11Verified
- bd_49c9872bc3fd7264New Hampshire State AGfiled 2024-12-13(2d gap)Verified
- bd_daeb670bbf3e3f52Oregon State AGfiled 2024-12-13(2d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_bac8660828954ab9Vermont State AGfiled 2024-12-16(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-595939
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 11, 2024
- Raw hash
- f19ec24ec8542fe13fc0d6835877b255d0342dad99b7e83b168f7d11acd35493
Reporting entity
- Name
- BYTE FEDERAL, INC.norm: byte federal
- Domain
- bytefederal.com
Victim entity
- Name
- BYTE FEDERAL, INC.norm: byte federal
- Domain
- bytefederal.com
Incident
- Discovered
- Nov 18, 2024
- Materiality determined
- —
- Notification sent
- Dec 1, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTBIOMETRIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Cooperating with law enforcement
- Third party
- via Third-party software provider
- Initial access
- supply_chain
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 13d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 18, 2024→ Notified: Dec 1, 202413d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.