HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
First Rate Financial
bd_4a19a89084c62698 · schema v1 · pii pii-v1
Full breach record for First Rate Financial →First Rate Financial notified Massachusetts residents of a data incident involving unauthorized access to personal information, including names, Social Security numbers, driver's license numbers, and financial account data. The company disconnected its network, engaged forensic specialists, reset passwords, and reported the incident to federal law enforcement. No fraud was reported.
Leak gap clock✗ Leak >180d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lockbit5 about this victim predates this filing by 203 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_8b2bd6b0246836d9Leak Sitelockbit5filed 2025-10-10(203d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_048ca57b3a6dbba9Vermont State AGfiled 2026-05-06(5d gap)Verified
- bd_0d2e50891960c490Indiana State AGfiled 2026-05-06(5d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-715-first-rate-financial/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- c83955015569ce76a9a92c4263b2f0b00f753bbf6e3c16910b65d1c16206ff45
Reporting entity
- Name
- First Rate Financialnorm: first rate financial
- Domain
- firstrateak.com
Victim entity
- Name
- First Rate Financialnorm: first rate financial
- Domain
- firstrateak.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- Leak >180d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.