DisclosureLens
HackingFinancial ServicesFinanceIdentity (basic)Government IDCritical

AUTOPAY Direct, Inc.

bd_702f47d2350c448f · schema v1 · pii pii-v1

Severity

Critical

Discovered

Feb 5, 2022

Filed

Apr 14, 2022

To disclose

10 weeks

Affected · nationwide

160,24753 in this filing

Linked

8 filings

Confidence

65%
Full breach record for AUTOPAY Direct, Inc.2 incidents on file

AUTOPAY Direct, Inc. reported a data breach affecting 160,247 individuals, which was discovered on February 5, 2022. The incident, an external system breach, occurred on February 2, 2022. The compromised information included names and driver's license or non-driver identification card numbers. Affected individuals were notified on April 11, 2022.

Maine clockDiscovered Feb 5, 2022Filed with AG Apr 14, 202268d ME AG >30d10 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 3 days
discovery → filing · 10 weeks / 68 days

Feb 2, 2022

Begins

Feb 5, 2022

Discovered

Apr 14, 2022

Filed

vs. sector median

on median

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 103d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Jan 1 (IL), last Apr 26 (CA) — a 115-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.