HackingIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Advance America
bd_44194c52e6534a23 · schema v1 · pii pii-v1
Full breach record for Advance America →NCAS of Delaware, LLC (d/b/a Advance America) notified Delaware residents of a data security incident occurring on or around February 7, 2023. An unauthorized actor accessed corporate business records containing customer personal information, including names, Social Security numbers, and financial data. The company engaged third-party cybersecurity experts, reported the incident to law enforcement, and implemented enhanced security measures. Affected individuals were offered one year of identity monitoring services through Kroll.
Leak gap clock⏱ Leak >90d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 144 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_44ea510f141a9b17Vermont State AGfiled 2023-08-15Verified
- bd_324083bfac683e39Delaware State AGfiled 2023-08-14(1d gap)Candidate
- bd_fec8b5a3a4336c8eNew Hampshire State AGfiled 2023-08-21(6d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/08/ELN-18661-Purpose-Financial-2-Ad-CM-12m-r3prf.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 15, 2023
- Raw hash
- 0ae65a1a87b2a6b47f0ef6cc0a9a314d9c14669b050725630f4b8c43c2abaa6a
Reporting entity
- Name
- NCAS of Delaware, LLCnorm: ncas of delaware
Victim entity
- Name
- Advance Americanorm: advance america
- Domain
- advanceamerica.net
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported this incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Compliance flags
- Leak >90d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.