HackingFinancial ServicesFinanceSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Lyon Services Corp.
bd_4c1288f15be191f8 · schema v1 · pii pii-v1
Full breach record for Lyon Services Corp. →On July 8, 2024, Lyon Services Corp. dba Lyon Financial was alerted to a loss of customer data from a third-party provider. An investigation completed on August 26, 2024 revealed that personal information including names, Social Security Numbers, and driver's license numbers may have been accessed without authorization. A total of 217 individuals were affected (1 Maine resident). Notifications were sent on August 30, 2024. Identity protection services were offered via Cyberscout.
Maine clockDiscovered Aug 26, 2024 → Filed with AG Sep 3, 20248d ✓ ME AG ≤30d8 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/918c940a-9a4a-40bf-83cb-d3c103838c53.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 3, 2024
- Raw hash
- 63464f282de0ab73bed1281c0d3f7867911c0835c8969974c36e3e771f904246
Reporting entity
- Name
- Lyon Services Corp.norm: lyon services
- Industry
- Financial Services
Victim entity
- Name
- Lyon Services Corp.norm: lyon services
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Aug 26, 2024
- Materiality determined
- —
- Notification sent
- Aug 30, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified Indiana Attorney General Todd Rokita per Indiana data breach notification statuteReported incident to federal law enforcement
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 8d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 26, 2024→ Filed with AG: Sep 3, 20248d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.