HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
ON DECK CAPITAL, INC.
bd_5174f877f9b1f2d6 · schema v1 · pii pii-v1
Full breach record for ON DECK CAPITAL, INC. →On March 10, 2022, On Deck Capital detected suspicious activity on internal computers and took them offline. An unauthorized actor copied data to a private cloud storage account, which OnDeck later secured and disabled. The data included names, SSNs, tax IDs, driver's license/passport numbers, financial account numbers, and medical/health insurance information. OnDeck engaged cybersecurity experts, notified the FBI, reset credentials, and enhanced security controls. Affected individuals were offered two years of identity monitoring.
California clockDiscovered Mar 10, 2022 → Notified Jun 2, 202284d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0f741100678b3176Maine State AGfiled 2022-06-03Candidate
- bd_4c76f7c6121633d9Montana State AGfiled 2022-06-03Verified
- bd_6de064587d52a836Washington State AGfiled 2022-06-03Verified
- bd_da3140a54da72e3fOregon State AGfiled 2022-06-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554013
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 3, 2022
- Raw hash
- d4fd66891a4838d6e14b37742ed3448a98da6b8626819b2e84f3581ef11e74f8
Reporting entity
- Name
- ON DECK CAPITAL, INC.norm: on deck
Victim entity
- Name
- ON DECK CAPITAL, INC.norm: on deck
Incident
- Discovered
- Mar 10, 2022
- Materiality determined
- —
- Notification sent
- Jun 2, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 10, 2022→ Notified: Jun 2, 202284d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.