DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsCapture App DataSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIdentity (basic)Government IDMediumContained

Funding Circle USA, Inc. (Dun & Bradstreet, Inc.)

bd_c6ddb79bfb378989 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Mar 30, 2018

To disclose

Affected

Not disclosed

Linked

3 filings

Confidence

75%
Full breach record for Funding Circle USA, Inc. (Dun & Bradstreet, Inc.)2 incidents on file

A data vendor serving Funding Circle USA experienced unauthorized access to employee email accounts hosted in Microsoft Office 365. The vendor identified the activity in November 2017 and determined Funding Circle customer data was in a compromised account on February 20, 2018. Affected data includes names, addresses, phone numbers, and Social Security numbers. The vendor engaged forensic investigators, notified law enforcement, and implemented MFA and enhanced security controls.

Incident timeline

Jun 1, 2017

Begins

Mar 30, 2018

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
New Hampshire State AGMar 23 · first
California State AG+7d · this page

Pattern: first filing Mar 23 (NH), last Mar 30 (CA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.