HackingStolen CredentialsData ExfiltratedData PublishedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
DAVE INC.
bd_96afc6c3b4dc3c74 · schema v1 · pii pii-v1
Full breach record for DAVE INC. →Dave, Inc. disclosed a data breach occurring between June 23 and July 1, 2020, resulting from a compromise at a third-party service provider. The incident exposed customer PII including names, emails, phone numbers, dates of birth, physical addresses, and encrypted Social Security numbers. Hashed passwords were also stolen and potentially cracked. No financial account or credit card data was accessed. Dave notified the FBI, engaged forensic investigators, reset credentials, and offered credit monitoring via Mastercard ID Theft Protection.
California clockDiscovered Jul 1, 2020 → Notified Aug 21, 202051d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5e95299fb85377f6Washington State AGfiled 2020-08-20Candidate
- bd_ea97508608d29423Oregon State AGfiled 2020-08-20Verified
- bd_e092890dc5d3fb2aDelaware State AGfiled 2020-08-21(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193343
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 20, 2020
- Raw hash
- 71fb0e4745b8d69bf2b21bf351fc10349202e9f16c8c11117e6541855fcdc8f6
Reporting entity
- Name
- DAVE INC.norm: dave
Victim entity
- Name
- DAVE INC.norm: dave
Incident
- Discovered
- Jul 1, 2020
- Materiality determined
- —
- Notification sent
- Aug 21, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement, including the Federal Bureau of Investigation ("FBI")
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 51d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 1, 2020→ Notified: Aug 21, 202051d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.