DisclosureLens
AccidentalFinancial ServicesFinanceMisconfigurationCustomer Data InvolvedIdentity (basic)Government IDMediumResolved

Noblr Reciprocal Exchange

bd_9f4988550e1c19de · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 21, 2021

Filed

May 10, 2021

To disclose

16 weeks

Affected

65state residents only

Linked

3 filings

Confidence

67%
Full breach record for Noblr Reciprocal Exchange

Noblr Reciprocal Exchange notified the NH Attorney General of a data security event involving unauthorized access to consumer personal information via its public-facing web quotes feature. On January 21, 2021, Noblr detected unusual quote activity and bot traffic intended to scrape driver's license numbers inadvertently included in unredacted page source code. The incident affected at least 65 New Hampshire residents. Noblr masked driver's license numbers and other PII in source code and application pages, blocked suspicious IPs, and adjusted rate limits. Free identity theft protection services were offered.

Incident timeline

discovery → filing · 16 weeks / 109 days

Jan 21, 2021

Discovered

May 10, 2021

Filed

vs. sector median

+7 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Maine State AGMay 7 · first
New Hampshire State AG+3d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.