HackingStolen CredentialsData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Paysafe Group Holdings Limitedd
bd_a7e7764a6bda2706 · schema v1 · pii pii-v1
Full breach record for Paysafe Group Holdings Limitedd →Paysafe Group Holdings Limited notified South Carolina of a cybersecurity incident affecting a legacy website used by Merchant Services. Unauthorized actors submitted automated queries between May 2018 and November 2020, potentially accessing names, contact details, SSNs, and bank account information. Paysafe engaged forensics, notified law enforcement, closed the site, and offered two years of credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1151afe21cdd47ffWashington State AGfiled 2020-12-16Verified
- bd_1c3042be6747728bCalifornia State AGfiled 2020-12-16Verified
- bd_6a289d8c42bb094cMaine State AGfiled 2021-01-12(27d gap)Verified
- bd_8e5980705d10b8f5Oregon State AGfiled 2021-01-19(34d gap)Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2020/PaysafeGroup.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2020
- Raw hash
- 429fc51f6aff0590996f133314916fdcb153e711cf026be6cc84d605180fe5a3
Reporting entity
- Name
- Paysafe Group Holdings Limiteddnorm: paysafe group holdings limitedd
Victim entity
- Name
- Paysafe Group Holdings Limiteddnorm: paysafe group holdings limitedd
Incident
- Discovered
- Nov 6, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.