HackingVulnerability ExploitCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
Aven Financial, Inc.
bd_c1f5906b42b7eac2 · schema v1 · pii pii-v1
Full breach record for Aven Financial, Inc. →Aven Financial, Inc. notified California residents that a security researcher gained unauthorized access to an internal, in-development storage system on July 17, 2023, via a temporary vulnerability. The researcher disclosed the issue within 45 minutes, and Aven remediated the vulnerability immediately. Affected data may include names, SSNs, driver's license numbers, and dates of birth. No passwords were accessed. Aven is offering 24 months of complimentary credit protection services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3ffe616a2c045d6aOregon State AGfiled 2023-07-29(1d gap)Verified
- bd_8773e72dbac0b13dMontana State AGfiled 2023-07-29(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571023
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- aaf898eb87d92e58142c9aadc9244c865badb118869a1c25a2617e3ebd963f89
Reporting entity
- Name
- Aven Financial, Inc.norm: aven financial
- Domain
- aven.com
Victim entity
- Name
- Aven Financial, Inc.norm: aven financial
- Domain
- aven.com
Incident
- Discovered
- Jul 17, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 days(11 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.