U.S. Cellular Corporation
bd_7cb9457bce354133 · schema v1 · pii pii-v1
U.S. Cellular filed a supplemental notice with the New Hampshire AG regarding a credential stuffing attack starting in April 2017. The incident exposed customer names, addresses, phone numbers, SSNs, and ACH/bank account data. Approximately 1,852 customers were affected, including 62 in NH. U.S. Cellular reset passwords, disabled accounts for former customers, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 1, 2017
Begins
Jun 27, 2017
Discovered
Oct 24, 2017
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_77bc7ae00b5b548e2017-10-24Verified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.