HackingStolen CredentialsCapture Stored DataData ExfiltratedData PublishedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Transak, Inc.
bd_81c6f6b6647441e3 · schema v1 · pii pii-v1
Full breach record for Transak, Inc. →Transak USA LLC notified Maryland AG of a data breach impacting 23,113 customers, including 554 Maryland residents. On Sept 23, 2024, an unknown actor compromised a single employee's credentials to access a third-party data host. The actor acquired and later published names and driver's license numbers. Transak engaged CrowdStrike, notified FBI/DHS, and offered credit monitoring. Remediation included MFA, VPN enhancements, and vendor audits.
Maryland clock✗ MD AG >90d23 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3419009e5cf78b81New Hampshire State AGfiled 2025-02-28Verified
- bd_761ade3211135d85Vermont State AGfiled 2025-02-28Verified
- bd_ade85d7f854c6681Indiana State AGfiled 2025-02-28Verified
- bd_ffe97878a4cef686California State AGfiled 2025-02-28Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376431.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 28, 2025
- Raw hash
- 9bc5d20ac9c1e2a0b59af2b5a01a8ceb5e5f5fb4fe7ad3c3ac30d5d37a282832
Reporting entity
- Name
- Kennedys CMK LLPnorm: kennedys cmk
Victim entity
- Name
- Transak, Inc.norm: transak
Incident
- Discovered
- Sep 23, 2024
- Materiality determined
- —
- Notification sent
- Feb 28, 2025
- Affected individuals
- 23,113
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney GeneralContacted Department of Homeland SecurityContacted the FBI
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 weeks(158 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.