HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Progrexion ASG, Inc.
bd_c7acddbaaa1c8df2 · schema v1 · pii pii-v1
Full breach record for Progrexion ASG, Inc. →Progrexion ASG, Inc. disclosed a data incident affecting California residents. A malicious third party exploited public-facing platforms between March 3 and April 22, 2021, to access FICO scores, account numbers, and limited account details. Progrexion took platforms offline, notified the NCCIC, and provided 24 months of TransUnion TrueIdentity protection. No SSNs or passwords were accessed from Progrexion.
California clockDiscovered Apr 8, 2021 → Notified Jun 9, 202162d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_758cf1ceced1c391Delaware State AGfiled 2021-06-16(7d gap)Verified
- bd_65824fe445e8ec0bOregon State AGfiled 2021-05-26(14d gap)Candidate
- bd_3c997f440ca227c4Maine State AGfiled 2021-07-12(33d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541705
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 9, 2021
- Raw hash
- 8e6dc08be2eb2c6388244cfbb9fa1ca07300da7a4190a025a5cb003f3b1a0984
Reporting entity
- Name
- Progrexion ASG, Inc.norm: progrexion asg
Victim entity
- Name
- Progrexion ASG, Inc.norm: progrexion asg
Incident
- Discovered
- Apr 8, 2021
- Materiality determined
- —
- Notification sent
- Jun 9, 2021
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the National Cybersecurity Communications and Integration Center (NCCIC)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- CA 60-day late · 62d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 8, 2021→ Notified: Jun 9, 202162d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.