DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsTargetedPIIIdentity (basic)LowContained

C2 Financial Corporation

bd_52aca2f42e5dfd07 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 25, 2026

Filed

Jun 2, 2026

To disclose

5 weeks

Affected

53state residents only

Confidence

67%
Full breach record for C2 Financial Corporation

C2 Financial notified Idaho AG of a phishing incident on April 25, 2026, where an unauthorized individual accessed a Quantum Reverse user account via device-code phishing. Approximately 53 Idaho consumers' PII was potentially accessed. C2 secured the account, reset credentials, and offered 24 months of credit monitoring.

Incident timeline

discovery → filing · 5 weeks / 38 days

Apr 25, 2026

Begins

Apr 25, 2026

Discovered

Jun 2, 2026

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed53 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.