HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Nationwide Recovery Services, Inc.
bd_c8ce5ede9daa4c73 · schema v1 · pii pii-v1
Full breach record for Nationwide Recovery Services, Inc. →TRG, LLC reported a data security incident involving its third-party vendor, Nationwide Recovery Services, Inc. An unauthorized party accessed Nationwide's network between July 5-11, 2024, exfiltrating patient data including names, SSNs, DOBs, account balances, and medical info. TRG, a medical imaging debt collector, notified affected individuals on June 16, 2025, offering 12 months of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3d33de89fc823ff9California State AGfiled 2025-06-18Verified
- bd_efbd11eb7175f863Maine State AGfiled 2025-05-16(33d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/trg-nationwide-recovery-services-20250618.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2025
- Raw hash
- a1666a51c207aa75b295ae9e011b3580ea495ab6fab8632b61993d6efcfac886
Reporting entity
- Name
- TSG Enterprises, LLCnorm: tsg enterprises
Victim entity
- Name
- Nationwide Recovery Services, Inc.norm: nationwide recovery
Incident
- Discovered
- Mar 31, 2025
- Materiality determined
- —
- Notification sent
- Jun 16, 2025
- Affected individuals
- 22
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General of the State of New JerseyNotified Attorney General of the State of New Hampshire
- Third party
- via Nationwide Recovery Services, Inc.
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.