MisusePrivilege AbuseEmployee Data InvolvedTargetedPIIIDENTITY_BASICLowContained
Credit Acceptance Corporation
bd_9901c6bf6b509eb5 · schema v1 · pii pii-v1
Full breach record for Credit Acceptance Corporation →Credit Acceptance Corporation notified the Maryland Attorney General of a security event involving an insider agent who used valid customer account access to solicit unauthorized payments via text message. The incident affected 3 Maryland consumers between December 3 and 11, 2024. The agent was terminated, and no sensitive data (SSN, bank info) was accessed.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376179.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 00f6501f6a391467da278f1b34d5d6aa5bea085b7c3d17b2ce62516f573a735b
Reporting entity
- Name
- Credit Acceptance Corporationnorm: credit acceptance
- Domain
- creditacceptance.com
Victim entity
- Name
- Credit Acceptance Corporationnorm: credit acceptance
- Domain
- creditacceptance.com
Incident
- Discovered
- Dec 20, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalFinancial
- Regulator citations
- Provided notice to Maryland Office of Attorney General
- Initial access
- insider_action
Compliance
- Time to disclose
- 47 weeks(328 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.