DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Acorn Financial Services, Inc.

bd_ea37c8dcec81c3d3 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 22, 2022

Filed

Aug 9, 2022

To disclose

16 weeks

Affected

1state residents only

Confidence

67%
Full breach record for Acorn Financial Services, Inc.2 incidents on file

Acorn Financial Services notified Montana residents of a security incident on April 22, 2022, involving unauthorized access to an employee's email account via phishing. The incident potentially exposed personal information including names, addresses, SSNs, driver's license numbers, and financial account numbers. Acorn secured the account, launched an investigation, and provided 12 months of complimentary identity monitoring through Kroll.

Incident timeline

discovery → filing · 16 weeks / 109 days

Apr 22, 2022

Discovered

Aug 9, 2022

Filed

vs. sector median

+7 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.