HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Used Bikes Direct, LLC
bd_486f611ee9a2d6ca · schema v1 · pii pii-v1
Full breach record for Used Bikes Direct, LLC →Used Bikes Direct, LLC notified New Hampshire residents that a third-party credit platform account (CRSS Credit API) was compromised between January 17, 2025, and March 2025. The attacker used stolen credentials to view historical consumer credit reports. The company blocked access, offered free credit monitoring via Cyberscout, and determined on April 4, 2025, that specific individuals' data was accessible.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0d931829eaaef72eIdaho State AGfiled 2025-05-12Candidate
- bd_72dd0eca397c56caIndiana State AGfiled 2025-05-12Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/used-bikes-direct-20250512.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 12, 2025
- Raw hash
- c2f4c948d5d4375608b5590f17f9ff79f16b72d338933e77927cefa8425850fd
Reporting entity
- Name
- Used Bikes Direct, LLCnorm: used bikes direct
Victim entity
- Name
- Used Bikes Direct, LLCnorm: used bikes direct
Incident
- Discovered
- Mar 1, 2025
- Materiality determined
- Apr 4, 2025
- Notification sent
- May 9, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.