HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Indastrial Acceptance Corporation
bd_64f9be54f5cdd9c6 · schema v1 · pii pii-v1
Full breach record for Indastrial Acceptance Corporation →Industrial Acceptance Corporation notified Rhode Island residents of a data breach discovered on February 24, 2025. The company became aware of unauthorized activity and took systems offline. On or around March 4, 2025, it was learned that files were taken from the network by an unauthorized actor. A review completed on May 11, 2026, determined that 808 Rhode Island residents' personal information was involved. The company engaged cybersecurity specialists, reported to federal law enforcement, and is offering 12 months of credit monitoring.
California clockDiscovered Feb 24, 2025 → Notified May 28, 2026458d ✗ CA 60-day late15 months discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_09c40eae3676c196Leak Siteakirafiled 2025-02-27(455d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_79cfa0ac16eea454Texas State AGfiled 2026-05-29(1d gap)Verified
- bd_b48acdbe47a03a88Massachusetts State AGfiled 2026-05-01(27d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624075
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 28, 2026
- Raw hash
- fae5948c6629871839475ce35dbcb62596299dcafc7db8e15906cd1df53141e5
Reporting entity
- Name
- Indastrial Acceptance Corporationnorm: indastrial acceptance
- Domain
- iaccredit.com
Victim entity
- Name
- Indastrial Acceptance Corporationnorm: indastrial acceptance
- Domain
- iaccredit.com
Incident
- Discovered
- Feb 24, 2025
- Materiality determined
- —
- Notification sent
- May 28, 2026
- Affected individuals
- 808
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the event to federal law enforcement
Compliance
- Time to disclose
- 15 months(458 days from discovery to filing)
- Compliance flags
- CA 60-day late · 458dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 24, 2025→ Notified: May 28, 2026458d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: May 28, 2026→ AG copy submitted: May 28, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.