HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Progressive Leasing Lease-to-Own
bd_9c14cbb322c10271 · schema v1 · pii pii-v1
Full breach record for Progressive Leasing Lease-to-Own →Progressive Leasing experienced a cybersecurity incident on September 11, 2023, where an unauthorized third party gained access to its network starting September 9, 2023. The breach affected personal information of customers and employees, including names, addresses, phone numbers, Social Security numbers, dates of birth, and email addresses. The company engaged cybersecurity experts, notified law enforcement, and is offering 12 months of complimentary credit monitoring and identity restoration services through Experian. The investigation remains ongoing.
California clockDiscovered Sep 11, 2023 → Notified Oct 23, 202342d ✓ CA 60-day OK6 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1d1b9dd739810e98Montana State AGfiled 2023-10-23(1d gap)Verified
- bd_2343ba4ecbd94ae8Oregon State AGfiled 2023-10-23(1d gap)Verified
- bd_acf2552b7336114eDelaware State AGfiled 2023-10-23(1d gap)Verified
- bd_2047ab3d4f323b6cWashington State AGfiled 2023-10-24(2d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 31d gap
- bd_707166e8373b559aNew Hampshire State AGfiled 2023-10-30(8d gap)Verified
- bd_981201c9f13646f0SEC 8-Kfiled 2023-09-21(31d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-575510
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 22, 2023
- Raw hash
- c000afe6330ad2ba425e683b2459a76ae6581cf925996569c46b1e4680e4a7cd
Reporting entity
- Name
- Progressive Leasing Lease-to-Ownnorm: progressive leasing lease to own
- Domain
- progleasing.com
Victim entity
- Name
- Progressive Leasing Lease-to-Ownnorm: progressive leasing lease to own
- Domain
- progleasing.com
Incident
- Discovered
- Sep 11, 2023
- Materiality determined
- —
- Notification sent
- Oct 23, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 42d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 11, 2023→ Notified: Oct 23, 202342d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.