ComplyRight
bd_a24e0da7536f0da9 · schema v1 · pii pii-v1
Full breach record for ComplyRight →ComplyRight, Inc. disclosed a cybersecurity incident where unauthorized access to its website occurred between April 20 and May 22, 2018. The company discovered the issue on May 22, 2018, disabled the platform, and engaged forensic investigators. Personal information including names, addresses, SSNs, and contact details was accessed. The company offered 12 months of credit monitoring via TransUnion.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 20, 2018
Begins
May 22, 2018
Discovered
Jul 24, 2018
Filed
vs. sector median
10 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Massachusetts State AGbd_7f79661b9712d7072018-07-24Verified
- Hawaii State AGbd_24a74f3f3d61b6852018-07-25 · +1dVerified
- Oregon State AGbd_3a041c49d3f4d0c22018-07-25 · +1dVerified
- California State AGbd_1c54d5a1341ed63f2018-07-19 · +5dVerified
Show 3 more filings ↓Show fewer ↑up to 12d gap
- New Hampshire State AGbd_3cc02a1b1fb285562018-07-13 · +11dVerified
- Washington State AGbd_ceca03da7c7029f32018-07-13 · +11dVerified
- Montana State AGbd_f9b984c81b6a84802018-07-12 · +12dCandidate
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jul 12 (MT), last Jul 25 (OR) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.