DisclosureLens
AccidentalFinancial ServicesFinanceMisdeliveryCustomer Data InvolvedIdentity (basic)Government IDHighContained

Activehours, Inc.

bd_6974fc10a12fe678 · schema v1 · pii pii-v1

Severity

High

Discovered

Oct 14, 2025

Filed

Nov 12, 2025

To disclose

29 days

Affected

3,412state residents only

Linked

2 filings

Confidence

69%
Full breach record for Activehours, Inc.

Activehours, Inc. d/b/a EarnIn reported an unauthorized access incident in Washington affecting 3,412 residents. From April 16 to October 15, 2025, encrypted personal information (name, DOB, address, SSN) of Lead Bank customers was sent to a partner bank. Discovered October 14, 2025. No evidence of misuse.

Washington clock WA AG ≤30d29 days discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 181 days
discovery → filing · 29 days

Apr 16, 2025

Begins

Oct 14, 2025

Discovered

Nov 12, 2025

Filed

vs. sector median

4 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Texas State AGNov 12 · first
Washington State AGNov 12 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.