BYTE FEDERAL, INC.
ent_019e20cf21e07cbedcc254d2fa3b13e1
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
58,000
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BYTE FEDERAL, INC.
- Normalized
- byte federal— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 9845009V55F6373C1E74
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- Vermont State AGas victim2024-12-16
Byte Federal disclosed a security breach on November 18, 2024, where a bad actor gained unauthorized access to a server by exploiting a vulnerability in third-party software. The company shut down its platform, isolated the actor, and secured the server. Customer PII, including government IDs and SSNs, was subject to unauthorized access, though no evidence of misuse was found. No user funds were compromised. Forensic investigation is ongoing.
- New Hampshire State AGas victim2024-12-13
Byte Federal Inc. reported a data breach discovered on November 18, 2024, where a bad actor exploited a third-party software vulnerability to gain unauthorized access to a server. The attacker encrypted data and acquired the encryption key. Approximately 58,000 customers nationwide were affected, including 182 in New Hampshire. Byte Federal shut down the platform, isolated the actor, reset credentials, and engaged forensic investigators. The investigation is ongoing.
- Oregon State AGas victim2024-12-13
Byte Federal Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-12-13. The breach occurred during 9/30/2024 - 11/18/2024. The breach was discovered on 11/18/2024. 58,000 individuals were affected. Notice was sent on 12/13/2024.
- South Carolina State AGas victim2024-12-13
Byte Federal disclosed a security breach on November 18, 2024, where a bad actor gained unauthorized access to a server by exploiting a third-party software vulnerability. The incident involved customer PII including names, SSNs, and government IDs. No funds were compromised. Byte Federal isolated the actor, reset credentials, and engaged forensic investigators.
- Montana State AGas victim2024-12-11
Byte Federal Inc. notified Montana residents of a security breach discovered on November 18, 2024. A bad actor gained unauthorized access to a server by exploiting a third-party software vulnerability. The incident involved customer PII including names, SSNs, and government IDs. No funds were compromised. Forensic investigation and law enforcement cooperation are ongoing.
- Massachusetts State AGas victim2024-12-11
Byte Federal Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-12-11. 791 Massachusetts residents were affected.
- California State AGas victim2024-12-11
Byte Federal Inc. disclosed a security breach discovered on November 18, 2024, where an unauthorized actor exploited a vulnerability in third-party software to access a server. The breach occurred on September 30, 2024. Affected data includes names, birthdates, addresses, phone numbers, emails, government-issued IDs, SSNs, transaction activity, and photographs. The company shut down its platform, isolated the attacker, reset customer accounts, and engaged forensic investigators. The investigation is ongoing.
- Maine State AGas victim2024-12-11
Byte Federal Inc. reported an external system breach (hacking) occurring on September 30, 2024, discovered on November 18, 2024. The incident involved unauthorized access to a server via a third-party software vulnerability. Approximately 58,000 individuals were affected, including 111 Maine residents. Data potentially exposed included names, SSNs, government IDs, and financial transaction activity. No user funds were compromised. Byte Federal shut down the platform, reset credentials, and engaged forensic investigators.
- Illinois State AGas victim2024-12-01
BYTE FEDERAL, INC filed a data-breach notice with the Illinois Attorney General in December 2024 (case 24-12-014). The register records the breach as discovered on September 30, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.