HackingStolen CredentialsCustomer Data InvolvedTargetedCREDENTIALSFINANCIAL_ACCOUNTLowContained
MoneyLion Inc.
bd_bd9750d69e9604b9 · schema v1 · pii pii-v1
Full breach record for MoneyLion Inc. →MoneyLion Inc. notified the New Hampshire Attorney General of a data incident affecting 3 state residents. Unauthorized parties used credentials compromised in a separate prior event to access user accounts between June 29 and July 30, 2021. MoneyLion locked affected accounts, sent notifications, and implemented MFA. No evidence of intrusion into MoneyLion's systems or theft of SSN/financial details from their servers was found.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_fa68bfa2655c20abMontana State AGfiled 2021-09-24(3d gap)Candidate
- bd_df340f584e21476aMaine State AGfiled 2021-10-01(4d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/moneylion-20210927.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 27, 2021
- Raw hash
- 6f416c8ab4b10eda9e894d381b2776fb3f6c08406856c628aa4febc7879345d2
Reporting entity
- Name
- MoneyLion Inc.norm: moneylion
Victim entity
- Name
- MoneyLion Inc.norm: moneylion
Incident
- Discovered
- Jun 29, 2021
- Materiality determined
- —
- Notification sent
- Jul 18, 2021
- Affected individuals
- 3
- Data types
- CREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.