HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCriticalContained
Progressive Leasing Lease-to-Own
bd_707166e8373b559a · schema v1 · pii pii-v1
Full breach record for Progressive Leasing Lease-to-Own →Progressive Leasing notified the New Hampshire Attorney General on October 30, 2023, of a cybersecurity incident discovered on September 11, 2023. The breach affected approximately 12,000 individuals, exposing customer and employee PII, including names, addresses, and financial account information. The company engaged forensic investigators and provided credit monitoring to affected parties. A related class-action settlement of $3.25 million was reported.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2047ab3d4f323b6cWashington State AGfiled 2023-10-24(6d gap)Verified
- bd_1d1b9dd739810e98Montana State AGfiled 2023-10-23(7d gap)Verified
- bd_2343ba4ecbd94ae8Oregon State AGfiled 2023-10-23(7d gap)Verified
- bd_acf2552b7336114eDelaware State AGfiled 2023-10-23(7d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 39d gap
- bd_9c14cbb322c10271California State AGfiled 2023-10-22(8d gap)Verified
- bd_981201c9f13646f0SEC 8-Kfiled 2023-09-21(39d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/progressive-leasing-20231030.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 30, 2023
- Raw hash
- f089430abb2a46e25acf6851b6d81ce58f905ba7a9e0907ce55bfd642cfbe265
Reporting entity
- Name
- Progressive Leasing Lease-to-Ownnorm: progressive leasing lease to own
- Domain
- progleasing.com
Victim entity
- Name
- Progressive Leasing Lease-to-Ownnorm: progressive leasing lease to own
- Domain
- progleasing.com
Incident
- Discovered
- Sep 11, 2023
- Materiality determined
- —
- Notification sent
- Oct 30, 2023
- Affected individuals
- 12,000
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.