HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSHighResolved
FlexShopper, LLC
bd_78f8f9ac2aeae15e · schema v1 · pii pii-v1
Full breach record for FlexShopper, LLC →FlexShopper, LLC reported a data security incident in California where a customer database was inadvertently accessible on the internet from August 25-30, 2017. Approximately 16,550 California residents were affected. Exposed data included names, SSNs, passwords, and financial account/payment card information. No evidence of misuse was found. FlexShopper engaged forensic investigators, took databases offline, and offered 12 months of credit monitoring to affected individuals.
California clockDiscovered Aug 30, 2017 → Notified Oct 3, 201734d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6aa7df82a8a2b2caMontana State AGfiled 2017-10-03Candidate
- bd_83d9b5291452e335Washington State AGfiled 2017-10-03Verified
- bd_1c2016df7fe6b54bOregon State AGfiled 2017-10-05(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-102351
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2017
- Raw hash
- f2c5310159c99bf616c7477e4be92e0766f724d52d74fbabfe46dbe05f304e3b
Reporting entity
- Name
- FlexShopper, LLCnorm: flexshopper
Victim entity
- Name
- FlexShopper, LLCnorm: flexshopper
Incident
- Discovered
- Aug 30, 2017
- Materiality determined
- —
- Notification sent
- Oct 3, 2017
- Affected individuals
- 16,550
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified California Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 34d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 30, 2017→ Notified: Oct 3, 201734d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.