AvidXchange, Inc.
bd_9ac136358f5b0f1d · schema v1 · pii pii-v1
Full breach record for AvidXchange, Inc. →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Payment software giant AvidXchange suffers its second ransomware attack of 2023. AvidXchange: Hackers have published sensitive data stolen from AvidXchange, a payment software company, following a second ransomware attack this year. The stolen data includes non-disclosure agreements, employee payroll information, and corporate bank account numbers. Login data has also been leaked, including usernames, passwords, and security question answers for various corporate systems. Easily guessable passwords suggest that the company uses lax security practices. AvidXchange confirmed that data was exfiltrated in April but refused to answer TechCrunch's questions regarding a potential ransom demand. Linked ransomware group: abyss.
P pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
May 4, 2023
Press report
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
If an SEC 8-K, state-AG notice or victim statement lands, DisclosureLens merges it into an incident and links it here.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
abyss
According to ransomware.live, Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk source code, that targets Windows and Linux/VMware ESXi systems using double-extortion tactics across healthcare, manufacturing, finance, and technology sectors — predominantly in North America.