HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Progressive Leasing Lease-to-Own
bd_acf2552b7336114e · schema v1 · pii pii-v1
Full breach record for Progressive Leasing Lease-to-Own →Progressive Leasing notified Delaware AG of a cybersecurity incident occurring September 9-11, 2023. An unauthorized third party accessed customer and employee files containing names, addresses, SSNs, and DOBs. The company engaged cybersecurity experts, notified law enforcement, and offered 12 months of Experian credit monitoring and identity restoration.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1d1b9dd739810e98Montana State AGfiled 2023-10-23Verified
- bd_2343ba4ecbd94ae8Oregon State AGfiled 2023-10-23Verified
- bd_2047ab3d4f323b6cWashington State AGfiled 2023-10-24(1d gap)Verified
- bd_9c14cbb322c10271California State AGfiled 2023-10-22(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 32d gap
- bd_707166e8373b559aNew Hampshire State AGfiled 2023-10-30(7d gap)Verified
- bd_981201c9f13646f0SEC 8-Kfiled 2023-09-21(32d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/11/Progressive-Leasing-Experian-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 23, 2023
- Raw hash
- 49bf0e70f807db9d3263701cc9bcbbcfa6824ff9fead3ccbc65ebf5076af2f8a
Reporting entity
- Name
- Progressive Leasing Lease-to-Ownnorm: progressive leasing lease to own
- Domain
- progleasing.com
Victim entity
- Name
- Progressive Leasing Lease-to-Ownnorm: progressive leasing lease to own
- Domain
- progleasing.com
Incident
- Discovered
- Sep 11, 2023
- Materiality determined
- —
- Notification sent
- Oct 23, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.