PROG Holdings, Inc.
ent_019ed2f6990409e4178dd068cd5798af
Disclosures
1
Leak Site · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- PROG Holdings, Inc.
- Normalized
- prog holdings— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001808834
- Domain
- None on record
Unverified threat-actor claim — not a regulatory filing
Attribution, victim identity, and counts shown here derive from a threat actor's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Disclosure history (1)newest first
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of PROG Holdings, Inc. — not by PROG Holdings, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- FEDERALSEC 10-K Item 1Cvia Progressive Leasing2026-02-18
Progressive Leasing disclosed a September 2023 cybersecurity incident affecting its systems. The company states there was no major operational impact and other subsidiaries were not affected. The incident is referenced in Item 1C of the 10-K filing as a cybersecurity risk. No specific details on the attack vector, data exfiltrated, or threat actor are provided.
- New Hampshire State AGvia Progressive Leasing2023-10-30
Progressive Leasing reported a cybersecurity incident where an unauthorized third party gained access to its network starting September 9, 2023. The breach affected personal information of 193,055 individuals, including 516 New Hampshire residents. The company engaged cybersecurity experts, notified law enforcement, and began mailing breach notices on October 23, 2023, offering credit monitoring services.
- Washington State AGvia Progressive Leasing2023-10-24
Progressive Leasing reported a cybersecurity incident where an unauthorized third party gained access to its network between September 9 and October 11, 2023. The breach affected 193,055 individuals, including 2,582 Washington residents. Stolen data included names, addresses, phone numbers, SSNs, dates of birth, and email addresses. Notices were mailed on October 23, 2023, offering credit monitoring.
- South Carolina State AGvia Progressive Leasing2023-10-24
Progressive Leasing notified South Carolina residents of a data breach where an unauthorized third party accessed the network starting September 9, 2023. Personal information including names, SSNs, DOBs, and addresses of customers and employees was accessed. The company engaged cybersecurity experts and notified law enforcement. Affected individuals are offered 12 months of credit monitoring via Experian.
- Montana State AGvia Progressive Leasing2023-10-23
Progressive Leasing notified Montana residents of a data breach where an unauthorized third party accessed the network between September 9-11, 2023. Personal information including names, SSNs, DOBs, and addresses of customers and employees was compromised. The company engaged cybersecurity experts, notified law enforcement, and offered 12 months of credit monitoring via Experian.
- Oregon State AGvia Progressive Leasing2023-10-23
Progressive Leasing reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-23. The breach occurred during 9/9/2023 - 9/11/2023. The breach was discovered on 9/11/2023. 193,055 individuals were affected. Notice was sent on 10/23/2023.
- Maine State AGvia Progressive Leasing2023-10-23
Financial services company Progressive Leasing reported that an external system breach occurred on September 9, 2023. The breach was discovered on September 11, 2023 and affected 488 Maine residents. The compromised information included names and Social Security Numbers. Progressive Leasing offered 12 months of credit monitoring and identity theft protection services through Experian.
- Delaware State AGvia Progressive Leasing2023-10-23
Progressive Leasing notified Delaware AG of a cybersecurity incident occurring September 9-11, 2023. An unauthorized third party accessed customer and employee files containing names, addresses, SSNs, and DOBs. The company engaged cybersecurity experts, notified law enforcement, and offered 12 months of Experian credit monitoring and identity restoration.
- Massachusetts State AGvia Progressive Leasing2023-10-23
Progressive Leasing reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-10-23. 2,541 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGvia Progressive Leasing2023-10-22
Progressive Leasing experienced a cybersecurity incident on September 11, 2023, where an unauthorized third party gained access to its network starting September 9, 2023. The breach affected personal information of customers and employees, including names, addresses, phone numbers, Social Security numbers, dates of birth, and email addresses. The company engaged cybersecurity experts, notified law enforcement, and is offering 12 months of complimentary credit monitoring and identity restoration services through Experian. The investigation remains ongoing.