Noblr Reciprocal Exchange
bd_9f4988550e1c19de · schema v1 · pii pii-v1
Full breach record for Noblr Reciprocal Exchange →Noblr Reciprocal Exchange notified the NH Attorney General of a data security event involving unauthorized access to consumer personal information via its public-facing web quotes feature. On January 21, 2021, Noblr detected unusual quote activity and bot traffic intended to scrape driver's license numbers inadvertently included in unredacted page source code. The incident affected at least 65 New Hampshire residents. Noblr masked driver's license numbers and other PII in source code and application pages, blocked suspicious IPs, and adjusted rate limits. Free identity theft protection services were offered.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 21, 2021
Discovered
May 10, 2021
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_93953ad731b87c972021-05-07 · +3dVerified
- Maine State AGbd_bc73eb4b9fc8a8442021-05-07 · +3dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.