HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Credit Sesame App
bd_ef07f5a37aad17c3 · schema v1 · pii pii-v1
Full breach record for Credit Sesame App →Credit Sesame, Inc. notified consumers of unauthorized account access involving suspicious log-in activity. The incident potentially exposed names and credentials. Credit Sesame secured accounts, investigated, and enhanced security controls. Affected individuals were offered complimentary credit monitoring through Experian. The notification was filed with the Vermont Attorney General on April 14, 2025.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a380913f6366514bIndiana State AGfiled 2025-04-14Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-14-credit-sesame-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 14, 2025
- Raw hash
- 83a5713563e32acf3f14cc2de88a212ddaa4bf1d3491c759ce4f93222c2720e2
Reporting entity
- Name
- Credit Sesame Appnorm: credit sesame app
- Domain
- creditsesameapp.com
Victim entity
- Name
- Credit Sesame Appnorm: credit sesame app
- Domain
- creditsesameapp.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Apr 14, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.