DisclosureLens
HackingTechnologyFinancial ServicesInformationStolen CredentialsCustomer Data InvolvedIdentity (basic)Financial accountCredentialsLowContained

Deluxe Corporation

bd_7fcac9b6ade56673 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Sep 3, 2019

To disclose

Affected

3state residents only

Confidence

66%
Full breach record for Deluxe Corporation2 incidents on file

Deluxe Corporation notified the NH Attorney General that a malicious third party used stolen credentials from the dark web to access the accounts of three New Hampshire residents on August 13, 2019. The compromised data included names, addresses, and bank account numbers. Deluxe is offering credit monitoring and implementing multi-factor authentication.

Incident timeline

Aug 13, 2019

Begins

Sep 3, 2019

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.