Springstone Financial
ent_05bbaefe4c5d7fc1c694ec5f
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
47,721
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Springstone Financial
- Normalized
- springstone financial— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Massachusetts State AGas victim2018-12-19
Springstone Financial reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-19. 146 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-12-18
Springstone Financial notified the NH AG of unauthorized access to web-based email accounts affecting ~26 NH residents. Data included PII, SSNs, bank info, and health data. No evidence of misuse. Actions: internal investigation, password resets, forensic retention, law enforcement contact, auth system changes, and 1-year identity protection offered.
- Oregon State AGas victim2018-12-14
Springstone Financial reported a data breach to the Oregon Attorney General. The breach was reported on 2018-12-14. The breach occurred during 7/27/2018 - 7/27/2018. The breach was discovered on 9/4/2018. 47,721 individuals were affected. Notice was sent on 12/14/2018.
- Montana State AGas victim2018-12-14
Springstone Financial reported a data breach to the Montana Attorney General. The breach was reported on 2018-12-14. The breach occurred from 7/27/2018 to 8/2/2018. 129 Montana residents were affected.
- California State AGas victim2018-12-14
Springstone Financial, LLC disclosed that an unauthorized third party accessed a limited number of web-based email accounts used by some employees between July 27 and August 2, 2018. The accounts contained personal information including names, addresses, Social Security numbers, bank account information, health-related information, and government ID numbers. The company reset passwords, retained forensic investigators, and contacted law enforcement. No evidence of data misuse was found.