AccidentalMisconfigurationCustomer Data InvolvedCREDENTIALSPIILowContained
ALLY FINANCIAL INC.
bd_a5f5a019f85d480f · schema v1 · pii pii-v1
Full breach record for ALLY FINANCIAL INC. →Ally Financial Inc reported a cybersecurity incident in California involving a programming code error on its website that exposed customer usernames and passwords. The breach was discovered on April 12, 2021. Ally locked affected passwords, updated the code, and engaged Equifax to provide 24 months of credit monitoring and identity theft insurance to affected customers. No fraudulent activity was found.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541863
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 15, 2021
- Raw hash
- 86439193b9b858c0127e86b4656c4a7e1ec14925c9bb51d8af62003b8da2c8e7
Reporting entity
- Name
- ALLY FINANCIAL INC.norm: ally financial
Victim entity
- Name
- ALLY FINANCIAL INC.norm: ally financial
Incident
- Discovered
- Apr 12, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1566.002 Spearphishing Link
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.