MisusePIIIDENTITY_BASICLowContained
American First Finance
bd_926b4460aaecd804 · schema v1 · pii pii-v1
Full breach record for American First Finance →FinWise Bank disclosed a data security incident involving a former employee who accessed American First Finance (AFF) data after employment ended. The incident, occurring on May 31, 2024, impacted consumer data held by AFF, a technology provider for FinWise installment loans. Affected data included full names. FinWise engaged forensic investigators and is offering 12 months of free credit monitoring to affected consumers. The notice covers residents in multiple states including Delaware, Iowa, Maryland, New York, North Carolina, Oregon, DC, New Mexico, and Rhode Island.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_b34543d57f025cb0Indiana State AGfiled 2025-07-29Candidate
- bd_204ff99cdd8ddbceMaine State AGfiled 2025-09-12(45d gap)Candidate
- bd_ce142ad7c41172caOregon State AGfiled 2025-09-12(45d gap)Verified
- bd_075ea6b96f2d99f1Texas State AGfiled 2025-09-15(48d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/01/American_First_Finance_Consumer-Notice-PII-Breach.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 29, 2025
- Raw hash
- 2704d93da37723f184237d469d8d6cbd9e7910e8192d396f122fef42ab2b11fe
Reporting entity
- Name
- FinWise Banknorm: finwise bank
- Domain
- finwise.bank
Victim entity
- Name
- American First Financenorm: american first finance
- Domain
- americanfirstfinance.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.