HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
RiteCheck Cashing, Inc.
bd_a94698f45a2cc180 · schema v1 · pii pii-v1
Full breach record for RiteCheck Cashing, Inc. →RiteCheck Cashing Inc. notified consumers of a data security incident identified on August 25, 2024. An unauthorized user accessed a server containing PII, including SSNs, driver's licenses, financial account numbers, and health information. The company engaged forensic experts, reset passwords, and deployed endpoint monitoring. Identity theft protection services were offered to affected individuals.
Vermont clock✗ VT AG >45 bday13 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_93567a1801e303ffNew Hampshire State AGfiled 2025-09-29(3d gap)Verified
- bd_c0fc7d55113000f8New Hampshire State AGfiled 2025-08-01(56d gap)Verified
- bd_17523945622644bcVermont State AGfiled 2025-07-28(60d gap)Candidate
- bd_79020fdb718d2b96Maine State AGfiled 2025-07-28(60d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 60d gap
- bd_975a1ea150accb18Indiana State AGfiled 2025-07-28(60d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-26-ritecheck-cashing-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2025
- Raw hash
- ca0d85989dd7ec6684b950f4ebda7490795a56b59311ea73778ab7e145806a20
Reporting entity
- Name
- RiteCheck Cashing, Inc.norm: ritecheck cashing
Victim entity
- Name
- RiteCheck Cashing, Inc.norm: ritecheck cashing
Incident
- Discovered
- Aug 25, 2024
- Materiality determined
- —
- Notification sent
- Sep 26, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 months(397 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.