HackingIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Bread Financial Payments, Inc.
bd_a02d2cbeec1fb4f0 · schema v1 · pii pii-v1
Full breach record for Bread Financial Payments, Inc. →Bread Financial Payments, Inc. reported a cybersecurity incident on March 31, 2023, involving unauthorized access to customer Account Center portals. Attackers used compromised card numbers, ZIP codes, and the last four digits of SSNs to redeem Cash Back rewards. The company blocked access, replaced cards, and restored rewards. Affected individuals were offered 12 months of credit monitoring via Experian.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3c359a961b62efe0Maine State AGfiled 2023-05-22Candidate
- bd_6864ff4c1631a383Montana State AGfiled 2023-05-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567072
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 22, 2023
- Raw hash
- 845344e5809a1d75f5ba9d6cc3f822d7c878eae88a06a1eff7deada2f66568b8
Reporting entity
- Name
- Bread Financial Payments, Inc.norm: bread financial payments
Victim entity
- Name
- Bread Financial Payments, Inc.norm: bread financial payments
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.