HackingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
ORDER EXPRESS, INC.
bd_c83602842b9c091e · schema v1 · pii pii-v1
Full breach record for ORDER EXPRESS, INC. →Order Express, Inc., a financial services provider based in Chicago, IL, experienced an external system breach (hacking) on July 29, 2022. The incident compromised the names and driver's license numbers of 63,220 individuals, including 5 Maine residents. The breach was discovered on November 18, 2022. Order Express notified affected consumers in writing on December 15, 2022, and offered 12 months of credit monitoring services.
Maine clockDiscovered Nov 18, 2022 → Filed with AG Dec 15, 202227d ✓ ME AG ≤30d27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_5a8e6539ed1675b9California State AGfiled 2022-12-15Candidate
- bd_87f8977af6ebf822Montana State AGfiled 2022-12-15Verified
- bd_d08c7863f9eb437fNew Hampshire State AGfiled 2022-12-15Verified
- bd_f03dcb3257aa924fWashington State AGfiled 2022-12-15Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1d501066-b1ca-4bbb-9500-5361bb73b1ac.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2022
- Raw hash
- ada52c45e4ddd067b3683d5331f79c2f4a0282903dabce599eae5ac491446aec
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- ORDER EXPRESS, INC.norm: order express
- Industry
- financial_services
Incident
- Discovered
- Nov 18, 2022
- Materiality determined
- —
- Notification sent
- Dec 15, 2022
- Affected individuals
- 63,220
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 27d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Nov 18, 2022→ Filed with AG: Dec 15, 202227d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.