AUTOPAY Direct, Inc.
bd_d2c472e50e865641 · schema v1 · pii pii-v1
Full breach record for AUTOPAY Direct, Inc. →2 incidents on fileAUTOPAY Direct, Inc. notified Montana residents of a ransomware incident where a threat actor infiltrated the network, exfiltrated PII (names, SSNs, driver's licenses, DOBs), and demanded ransom. The breach occurred from Oct 11, 2021, to Feb 5, 2022. AUTOPAY engaged forensic investigators, notified law enforcement, terminated access, and implemented MFA and enhanced security controls.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 11, 2021
Begins
Feb 5, 2022
Discovered
Mar 31, 2022
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Indiana State AGbd_e1528908ef61677d2022-04-11 · +11dVerified
- Washington State AGbd_27c3947e62aa6b162022-04-14 · +14dVerified
- South Carolina State AGbd_2c0e299e2e7ca1b02022-04-14 · +14dVerified
- Maine State AGbd_702f47d2350c448f2022-04-14 · +14dVerified
Show 3 more filings ↓Show fewer ↑up to 89d gap
- New Hampshire State AGbd_07d252a1f53fa0562022-04-18 · +18dVerified
- California State AGbd_29d55959bdbcd9252022-04-26 · +26dVerified
- Illinois State AGbd_2e2021ad759667742022-01-01 · +89dCandidate
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Apr 26 (CA) — a 115-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.