HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Benworth Capital Partners
bd_5debc63823b37a22 · schema v1 · pii pii-v1
Full breach record for Benworth Capital Partners →Benworth Capital Partners experienced a cybersecurity incident on May 16, 2025, when a criminal actor accessed systems via a third-party service provider. The company discovered stolen files on May 23, 2025. Affected data includes borrower names, addresses, taxpayer identification numbers (including SSNs), phone numbers, and loan account details. Benworth negotiated for the return of files and has contained the threat. Identity protection services via IDX are being offered to affected individuals.
California clockDiscovered May 23, 2025 → Notified Sep 16, 2025116d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_6f85607b15ec21a6Montana State AGfiled 2025-09-16Verified
- bd_a539b57158b4805bOregon State AGfiled 2025-09-16Verified
- bd_382048583884f3f8California State AGfiled 2025-10-31(45d gap)Verified
- bd_19509b4d1db730bcOregon State AGfiled 2025-11-04(49d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 55d gap
- bd_1ee7dc4631cacb01Texas State AGfiled 2025-11-04(49d gap)Verified
- bd_7108901f07475009Washington State AGfiled 2025-07-23(55d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-610012
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 16, 2025
- Raw hash
- 9fbcda6231a40679f4e3e7af97ccc6287a3b4be45c4cfe8769fd2150bd443d3c
Reporting entity
- Name
- Benworth Capital Partnersnorm: benworth capital
- Domain
- benworthcapital.com
Victim entity
- Name
- Benworth Capital Partnersnorm: benworth capital
- Domain
- benworthcapital.com
Incident
- Discovered
- May 23, 2025
- Materiality determined
- —
- Notification sent
- Sep 16, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- CA 60-day late · 116d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 23, 2025→ Notified: Sep 16, 2025116d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.