Pathward, N.A.
ent_63df97f7dae2ea42d5d7b25c
Disclosures
12
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
793,626
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Pathward, N.A.
- Normalized
- pathward na— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (12)newest first
- Montana State AGas victim2024-11-27
Pathward, N.A. experienced unauthorized electronic access to Spruce accounts between June 29 and August 4, 2024. Discovered August 2, 2024. Affected data included names and financial account numbers. Notices sent November 13, 2024. Credit monitoring offered via IDX.
- Montana State AGas reporting2023-10-04
Pathward, N.A., issuer of the H&R Block Emerald Card, notified customers of a data security incident involving third-party provider Progress Software's MOVEit Transfer tool. A previously unknown vulnerability was exploited, leading to unauthorized acquisition of personal information including names, SSNs, DOBs, driver's license numbers, and card details. Discovery occurred on July 12, 2023. Affected individuals were offered two years of identity monitoring via OnAlert.
- Indiana State AGas victim2023-05-27
Pathward, NA reported a data breach to the Indiana Attorney General. 25,948 Indiana residents were affected. 793,626 individuals affected in total.
- California State AGas victim2022-11-01
Pathward N.A. disclosed a data breach affecting its prepaid card customers. Unauthorized access occurred between September 4 and 12, 2022, via the third-party service provider Blackhawk Engagement Solutions' website (MyPrepaidCenter.com). The incident involved the acquisition of names, email addresses, phone numbers, card numbers, expiration dates, and CVV codes. Pathward blocked affected cards, issued replacements, and reported the incident to law enforcement.
- Massachusetts State AGas victim2022-11-01
Pathward N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-11-01. 4,270 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2022-11-01
Pathward, N.A. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-11-01. The breach occurred during 9/4/2022 - 9/12/2022. The breach was discovered on 9/11/2022. 165,727 individuals were affected. Notice was sent on 10/31/2022.
- Washington State AGas victim2022-11-01
Pathward N.A. reported a cyberattack affecting Washington residents. Unauthorized access occurred Sept 4-12, 2022, discovered Sept 11. Data exposed: names, emails, phone numbers, prepaid card numbers, expiration dates, and CVVs. 2,639 Washingtonians affected. Third-party provider Blackhawk Engagement Solutions was involved. Cards were blocked and reissued.
- South Carolina State AGas victim2022-11-01
Pathward, N.A. (via third-party provider Blackhawk Engagement Solutions) disclosed a data breach affecting MyPrepaidCenter.com profiles. Unauthorized access occurred Sept 4-12, 2022, exposing names, emails, phone numbers, and prepaid card details (numbers, expiration, CVV). Discovered Sept 11, 2022. Cards were blocked and reissued. Law enforcement notified.
- Maine State AGas victim2022-11-01
Pathward, N.A. reported an external system breach that occurred on September 4, 2022, and was discovered on September 11, 2022. The incident affected 691 Maine residents, compromising their names and financial account numbers with associated security codes or PINs.
- Indiana State AGas victim2022-10-31
Pathward, N.A reported a data breach to the Indiana Attorney General. The breach occurred on 2022-09-04 and was reported on 2022-10-31. 2,913 Indiana residents were affected. 165,727 individuals affected in total.
- Montana State AGas victim2022-10-31
Pathward, N.A. (via third-party provider Blackhawk Engagement Solutions) experienced unauthorized access to the MyPrepaidCenter.com website between Sept 4-12, 2022. Incident discovered Sept 11, 2022. Compromised data included names, emails, phone numbers, and prepaid card details (numbers, expiration, CVV). Cards were blocked and reissued. Law enforcement notified.
- Delaware State AGas victim2022-10-31
Blackhawk Engagement Solutions, a third-party provider for Pathward N.A., disclosed a data breach affecting MyPrepaidCenter.com. Unauthorized access occurred between September 4 and 12, 2022, exposing cardholder names, emails, phone numbers, prepaid card numbers, expiration dates, and CVV codes. Pathward blocked and reissued affected cards and notified law enforcement. Notices were sent on October 31, 2022.