ON Q FINANCIAL, LLC
bd_48330967f1459ecf · schema v1 · pii pii-v1
Full breach record for ON Q FINANCIAL, LLC →2 incidents on fileOn Q Financial, LLC notified clients of a data security incident where an unknown individual accessed their network via a vulnerability in ConnectWise's ScreenConnect software. The intrusion occurred on March 14, 2023, but was discovered on February 20, 2024, when ConnectWise notified On Q Financial of the vulnerability. Client personal information, including names and Social Security numbers, was exfiltrated. On Q Financial patched the vulnerability, engaged forensic investigators, reported the incident to the FBI, and is offering credit monitoring and fraud assistance to affected clients.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 14, 2023
Begins
Feb 20, 2024
Discovered
Mar 29, 2024
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitebianlianbd_ee592bde892a7b022024-04-06 · +8dVerified by operator
Regulatory filings (9) · sorted by filing gap
- Illinois State AGbd_bca121f6a23d98442024-04-01 · +3dVerified by operator
- Washington State AGbd_32dae1ae6ad3e6f42024-04-02 · +4dCandidate
- California State AGbd_47866e35155e8f932024-04-02 · +4dVerified by operator
- Maine State AGbd_70331c336a1897252024-04-02 · +4dVerified by operator
Show 5 more filings ↓Show fewer ↑up to 13d gap
- Montana State AGbd_bfba92634c81bbdc2024-04-02 · +4dVerified by operator
- South Carolina State AGbd_5fb90898a6e95a8e2024-04-03 · +5dVerified
- New Hampshire State AGbd_a5faead4f3404bf82024-04-03 · +5dVerified by operator
- Massachusetts State AGbd_d4ea7af3e6261a2d2024-04-03 · +5dVerified
- Oregon State AGbd_b11839235c04d95c2024-04-11 · +13dVerified
Showing first 10 of 13 linked disclosures.
Filing propagation · 10 filings · 10 states
View merged incident ↗Pattern: first filing Mar 29 (DE), last Apr 11 (OR) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 13 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.