HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
TMX Finance Corporate Services, Inc.
bd_489f453708ea6cf1 · schema v1 · pii pii-v1
Full breach record for TMX Finance Corporate Services, Inc. →TMX Finance Corporate Services, Inc. disclosed a data breach affecting customers of its TitleMax, TitleBucks, and InstaLoan brands. Suspicious activity was detected on February 13, 2023, with unauthorized access occurring between early December 2022 and mid-February 2023. The incident involved the acquisition of PII, including SSNs, driver's licenses, and financial account data. TMX retained forensic experts, notified the FBI, contained the incident, reset passwords, and offered 12 months of credit monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_14539223f1a1ef97Vermont State AGfiled 2023-03-30Verified
- bd_1dcc954f0889a511Delaware State AGfiled 2023-03-30Candidate
- bd_2847abc13900a9d1California State AGfiled 2023-03-30Verified
- bd_468db14b4701e66aWashington State AGfiled 2023-03-30Verified
Show 2 more filings ↓Show fewer ↑
- bd_b3ab13fb7ab5cf4fMontana State AGfiled 2023-03-30Verified
- bd_cc20dd88b5a827d7New Hampshire State AGfiled 2023-03-30Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/04/TMX-Finance-Sample-Copy-of-Individual-Notice-L01.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2023
- Raw hash
- 751a4fc376c631f8d6c6a3fa88830d81c4cf3306ec7bd13c9292a1ec861b2762
Reporting entity
- Name
- TMX Finance Family of Companiesnorm: tmx finance family of companies
- Domain
- tmxfinancefamily.com
Victim entity
- Name
- TMX Finance Corporate Services, Inc.norm: tmx finance corporate
Incident
- Discovered
- Feb 13, 2023
- Materiality determined
- —
- Notification sent
- Mar 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.