Progressive Leasing Lease-to-Own
ent_082f6588fc69ff11969506c4
Disclosures
8
SEC 10-K Item 1C · State AG · SEC 8-K · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
193,055
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Progressive Leasing Lease-to-Own
- Normalized
- progressive leasing lease to own— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- progleasing.com
- Corporate parent
- PROG Holdings, Inc.— as stated in the breach filing
Disclosure history (8)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-18
Progressive Leasing disclosed a September 2023 cybersecurity incident affecting its systems. The company states there was no major operational impact and other subsidiaries were not affected. The incident is referenced in Item 1C of the 10-K filing as a cybersecurity risk. No specific details on the attack vector, data exfiltrated, or threat actor are provided.
- ⛰️New Hampshire State AGas victim2023-10-30
Progressive Leasing notified the New Hampshire Attorney General on October 30, 2023, of a cybersecurity incident discovered on September 11, 2023. The breach affected approximately 12,000 individuals, exposing customer and employee PII, including names, addresses, and financial account information. The company engaged forensic investigators and provided credit monitoring to affected parties. A related class-action settlement of $3.25 million was reported.
- 🌲Washington State AGas victim2023-10-24
Progressive Leasing, a finance sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-09-11 and filed notice on 2023-10-24. 2,582 Washington residents were affected. 43 days elapsed between awareness and notification. 2 days to identify the breach. 30 days to contain the breach.
- 🦬Montana State AGas victim2023-10-23
Progressive Leasing reported a data breach to the Montana Attorney General. The breach was reported on 2023-10-23. The breach occurred on 9/11/2023. 40 Montana residents were affected.
- 🦫Oregon State AGas victim2023-10-23
Progressive Leasing reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-23. The breach occurred during 9/9/2023 - 9/11/2023. The breach was discovered on 9/11/2023. 193,055 individuals were affected. Notice was sent on 10/23/2023.
- 💎Delaware State AGas victim2023-10-23
Progressive Leasing notified Delaware AG of a cybersecurity incident occurring September 9-11, 2023. An unauthorized third party accessed customer and employee files containing names, addresses, SSNs, and DOBs. The company engaged cybersecurity experts, notified law enforcement, and offered 12 months of Experian credit monitoring and identity restoration.
- 🐻California State AGas victim2023-10-22
Progressive Leasing experienced a cybersecurity incident on September 11, 2023, where an unauthorized third party gained access to its network starting September 9, 2023. The breach affected personal information of customers and employees, including names, addresses, phone numbers, Social Security numbers, dates of birth, and email addresses. The company engaged cybersecurity experts, notified law enforcement, and is offering 12 months of complimentary credit monitoring and identity restoration services through Experian. The investigation remains ongoing.
- FEDERALSEC 8-Kas victim2023-09-21
PROG Holdings, Inc. reported a cybersecurity incident at its Progressive Leasing subsidiary. The investigation is ongoing, involving PII including SSNs of customers. The company engaged third-party experts and notified law enforcement. No material financial impact is currently expected.