HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
LENDUS, LLC
bd_f980748824188a16 · schema v1 · pii pii-v1
Full breach record for LENDUS, LLC →YouLend US LLC notified the California AG of unauthorized access to its network between June 5 and June 9, 2026. The company detected the disruption on June 9, 2026. Personal information including names, dates of birth, and Social Security numbers was acquired. The company engaged cybersecurity specialists, secured systems, and reported to law enforcement. Credit monitoring is being offered to affected individuals.
California clockDiscovered Jun 9, 2026 → Notified Jul 15, 202636d ✗ CA 30-day late5 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_184b8f1dc0796eadOregon State AGfiled 2026-07-15Verified
- bd_b0943eba6233f07cTexas State AGfiled 2026-07-17(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-626504
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2026
- Raw hash
- 022c0e4ecdfb9d84a3089d83d95e22308bd50b6e4c08dbd08dae0a1c75692dd1
Reporting entity
- Name
- LENDUS, LLCnorm: lendus
Victim entity
- Name
- LENDUS, LLCnorm: lendus
Incident
- Discovered
- Jun 9, 2026
- Materiality determined
- —
- Notification sent
- Jul 15, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to federal law enforcement and other authorities
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- CA 30-day late · 36dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 9, 2026→ Notified: Jul 15, 202636d 30 calendar days CA 30-day late California Consumers notified: Jul 15, 2026→ AG copy submitted: Jul 15, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.