HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
WESTERN UNION FINANCIAL SERVICES, INC.
bd_8fc621545c740b56 · schema v1 · pii pii-v1
Full breach record for WESTERN UNION FINANCIAL SERVICES, INC. →Western Union Financial Services, Inc. disclosed a data breach involving its third-party vendor, Accellion, accessed via compromised file transfer services used by The Kroger Co. Unauthorized access occurred between Dec 24-29, 2020, discovered Jan 23, 2021. Affected data included personal information from reports of money transfers initiated at Kroger retail locations. Western Union offered two years of Experian Identity Works. Systems were not directly compromised.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fa64d47849f6b119Maine State AGfiled 2021-03-17Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539192
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2021
- Raw hash
- 75ae206054f68066477594ddebf0568b5e7885d673e2c348679daad0638287e0
Reporting entity
- Name
- WESTERN UNION FINANCIAL SERVICES, INC.norm: western union financial
Victim entity
- Name
- WESTERN UNION FINANCIAL SERVICES, INC.norm: western union financial
Incident
- Discovered
- Jan 23, 2021
- Materiality determined
- Mar 17, 2021
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.