HackingStolen CredentialsCustomer Data InvolvedFINANCIAL_ACCOUNTLowActive
PalmFlex, Inc
bd_9ec6bf66561cd35f · schema v1 · pii pii-v1
Full breach record for PalmFlex, Inc →PalmFlex, Inc. notified Massachusetts customers on July 15, 2026, that payment card information may have been accessed by an unauthorized third party. The company engaged hosting providers and cybersecurity specialists to investigate, secure systems, reset credentials, and implement additional access restrictions. No specific count of affected individuals was provided.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1143-palmflex-inc/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2026
- Raw hash
- 5cded259a1fd09b3dbeab1373411819b41bd1ec523f850ca224b31a0ff054a45
Reporting entity
- Name
- PalmFlex, Incnorm: palmflex
Victim entity
- Name
- PalmFlex, Incnorm: palmflex
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 15, 2026
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.