CMS Companies
ent_08a669e3fded74c2ce6c1273
Disclosures
3
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,284
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CMS Companies
- Normalized
- cms companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cmsco.com
Disclosure history (3)newest first
- New Hampshire State AGas victim2022-02-22
CMS Companies filed a supplemental notice with the New Hampshire AG regarding a July 20, 2021 malware incident. The breach affected 51 NH residents, exposing names, SSNs, and financial data. CMS engaged forensic specialists, notified law enforcement, and provided 24 months of credit monitoring.
- Maine State AGas victim2022-02-04
CMS Companies, a financial services provider based in Wynnewood, PA, reported an external system breach (hacking) occurring between July 17 and July 20, 2021. The incident was discovered on January 4, 2022, affecting 2,284 individuals, including 3 Maine residents. The breach compromised names and financial account numbers (including credit/debit card numbers with security codes/PINs). CMS Companies sent written notifications on February 4, 2022, and provided 24 months of identity theft protection services through IDX.
- Indiana State AGas victim2022-02-04
CMS Companies reported a data breach to the Indiana Attorney General. The breach occurred on 2021-07-17 and was reported on 2022-02-04. 7 Indiana residents were affected. 2,284 individuals affected in total.