CUSO Financial Services, L.P.
bd_55bb67f5c342d233 · schema v1 · pii pii-v1
Full breach record for CUSO Financial Services, L.P. →CUSO Financial Services, LP reported that an unauthorized individual accessed one employee's account at a third-party service provider used for FINRA-required communication archiving. The access occurred between December 19, 2023, and January 19, 2024, when CUSO became aware of suspicious activity. The affected account contained customer names and other personal information. CUSO secured the account, reset passwords, engaged cybersecurity specialists, and notified federal law enforcement. Complimentary credit monitoring and identity restoration services are being offered to affected individuals.
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_5f808b59a614feadOregon State AGfiled 2024-10-28Candidate
- bd_af8d29e7a825abc2Maine State AGfiled 2024-10-28Verified
- bd_b7bc262cfb0f930aMontana State AGfiled 2024-10-28Verified by operator
- bd_c148a7a23112a55aNew Hampshire State AGfiled 2024-10-28Verified
Show 2 more filings ↓Show fewer ↑
- bd_c6c0f3798969948dWashington State AGfiled 2024-10-28Verified by operator
- bd_f79f964303bed083Indiana State AGfiled 2024-10-28Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-594024
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 28, 2024
- Raw hash
- 6eb13a7425a33cb3898a15210bc39d6648b431ab2a526c364369293f572d6317
Reporting entity
- Name
- CUSO Financial Services, L.P.norm: cuso financial
Victim entity
- Name
- CUSO Financial Services, L.P.norm: cuso financial
Incident
- Discovered
- Jan 19, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
- Third party
- via Third-party service provider for archiving communications
- Initial access
- supply_chain
Compliance
- Time to disclose
- 40 weeks(283 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.