DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsCustomer Data InvolvedCredentialsFinancial accountIdentity (basic)LowContained

FloatMe

bd_54811d05a129f6e3 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Jan 6, 2026

To disclose

Affected

2state residents only

Linked

4 filings

Confidence

65%
Full breach record for FloatMe

Float Me Inc. notified Massachusetts residents of a data breach occurring on December 8, 2025, where a malicious actor used credentials obtained from an unknown external source to improperly access user accounts. Affected data included login credentials, mailing addresses, phone numbers, and partial financial account details for a limited subset of consumers. The company reset passwords, blocked the actor, and cancelled fraudulent advances. MFA is recommended.

Incident timeline

Dec 8, 2025

Begins

Jan 6, 2026

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGJan 5 · first
Massachusetts State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.