HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
GardaWorld Cash U.S.
bd_b0ebb9df09562ad9 · schema v1 · pii pii-v1
Full breach record for GardaWorld Cash U.S. →GardaWorld Cash U.S. disclosed a cybersecurity incident affecting administrative files in its Florida facility. An unauthorized actor accessed systems between October 30, 2023, and November 16, 2023, copying administrative files containing names, SSNs, driver's license numbers, dates of birth, and health-related information. The company engaged external experts, secured systems, and offered two years of complimentary credit monitoring to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_0e1b21509eb07ef5Maine State AGfiled 2024-03-22Candidate
- bd_2688209c79606e8bCalifornia State AGfiled 2024-03-22Verified
- bd_518b38cdfe9dac68Delaware State AGfiled 2024-03-22Verified
- bd_740aa781d9cce1fdVermont State AGfiled 2024-03-22Verified
Show 4 more filings ↓Show fewer ↑
- bd_7416629fa1a9cccaOregon State AGfiled 2024-03-22Verified
- bd_ad65ae76f4ee4ad3Washington State AGfiled 2024-03-22Verified
- bd_bb072a3fa48d3523Indiana State AGfiled 2024-03-22Verified
- bd_fe76d026e22de983Montana State AGfiled 2024-03-22Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/04/GardaWorld-Cash.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2024
- Raw hash
- d08e2d5a0d7dd12c632afdacb6d025c5e849547007c21aeeb78259251947e25e
Reporting entity
- Name
- GardaWorld Cash U.S.norm: gardaworld cash us
Victim entity
- Name
- GardaWorld Cash U.S.norm: gardaworld cash us
Incident
- Discovered
- Nov 16, 2023
- Materiality determined
- —
- Notification sent
- Apr 1, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.