HackingFinancial ServicesFinanceStolen CredentialsCapture App DataSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Funding Circle USA, Inc. (Dun & Bradstreet, Inc.)
bd_c6ddb79bfb378989 · schema v1 · pii pii-v1
Full breach record for Funding Circle USA, Inc. (Dun & Bradstreet, Inc.) →A data vendor serving Funding Circle USA experienced unauthorized access to employee email accounts hosted in Microsoft Office 365. The vendor identified the activity in November 2017 and determined Funding Circle customer data was in a compromised account on February 20, 2018. Affected data includes names, addresses, phone numbers, and Social Security numbers. The vendor engaged forensic investigators, notified law enforcement, and implemented MFA and enhanced security controls.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3d87d952d97bbbadMontana State AGfiled 2018-03-30Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134928
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2018
- Raw hash
- 2b22647898fd81acb4085dfa21bed2f92898931bd8b69f163cf2f59e3ec0d89e
Reporting entity
- Name
- Funding Circle USA, Inc. (Dun & Bradstreet, Inc.)norm: funding circle usa inc dun bradstreet
- Domain
- fundingcircle.com
Victim entity
- Name
- Funding Circle USA, Inc. (Dun & Bradstreet, Inc.)norm: funding circle usa inc dun bradstreet
- Domain
- fundingcircle.com
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 1, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email CollectionT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via D&B (data vendor)
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.