DAVE INC.
ent_019e5ba9ad377f4c720a931262ea94b6
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
7,500,000
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DAVE INC.
- Normalized
- dave— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 25490061SUVXCW51RZ82
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Indiana State AGas victim2020-08-21
Dave Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-06-23 and was reported on 2020-08-21. 64,388 Indiana residents were affected. 7,500,000 individuals affected in total.
- New Hampshire State AGas victim2020-08-21
Dave, Inc. notified the NH Attorney General of a data breach involving ~4,806 NH residents. Unauthorized access occurred June 23–July 1, 2020, via a third-party service provider compromise. Exposed data included names, contact info, SSNs (encrypted), and hashed passwords. Dave engaged forensics, notified the FBI, reset credentials, and offered identity theft protection.
- Delaware State AGas victim2020-08-21
Dave, Inc. disclosed a data breach affecting customer records between June 23 and July 1, 2020, resulting from a compromise at a third-party service provider. The incident exposed names, emails, phone numbers, dates of birth, physical addresses, and encrypted Social Security numbers. Approximately 5,971 Rhode Island residents were specifically identified as affected. Dave notified the FBI, engaged forensic investigators, reset credentials, and offered credit monitoring.
- Washington State AGas victim2020-08-20
Dave, Inc. notified the Washington AG of a data breach affecting ~41,000 residents. Unauthorized access occurred June 23-July 1, 2020, via a former third-party service provider. Exposed data included names, emails, DOBs, addresses, and encrypted SSNs. Dave engaged forensic investigators, notified the FBI, reset credentials, and offered credit monitoring.
- California State AGas victim2020-08-20
Dave, Inc. experienced a data breach between June 23 and July 1, 2020, resulting from a compromise at a former third-party service provider. An unauthorized party accessed and stole customer data, including names, emails, phone numbers, hashed passwords, and encrypted Social Security numbers. The data was subsequently posted on illicit online marketplaces. Dave discovered the incident on July 1, 2020, secured systems, reset credentials, and engaged forensic experts and the FBI. Affected individuals were offered identity theft protection services.
- Oregon State AGas victim2020-08-20
Dave, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-08-20. The breach occurred during 6/23/2020 - 7/1/2020. The breach was discovered on 7/1/2020. 7,500,000 individuals were affected. Notice was sent on 8/21/2020.
- Illinois State AGas victim2020-01-01
DAVE, INC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-303). The register records the breach as discovered on July 1, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.