AUTOPAY Direct, Inc.
ent_827e3e95ef7911de6bf85bb8
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
160,247
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AUTOPAY Direct, Inc.
- Normalized
- autopay direct— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- California State AGas victim2022-04-26
AUTOPAY Direct, Inc. experienced a ransomware attack where a threat actor infiltrated its network and exfiltrated personally identifiable information (PII) of customers from February 2 to February 3, 2022. The company discovered the incident on February 5, 2022, when the actor demanded ransom. AUTOPAY did not pay the ransom, terminated unauthorized access, and engaged forensic investigators. Remediation included implementing MFA and enhanced security controls. Affected individuals were offered 12 months of Experian IdentityWorks.
- New Hampshire State AGas victim2022-04-18
AUTOPAY Direct, Inc. notified the NH Attorney General of a ransomware incident. A threat actor infiltrated the network, exfiltrated customer PII, and demanded ransom (not paid). Occurred Feb 2-3, 2022; discovered Feb 5, 2022. 62 NH residents affected. Forensic investigation conducted; MFA and enhanced security controls implemented.
- Washington State AGas victim2022-04-14
AUTOPAY Direct, Inc. reported a ransomware cyberattack in Washington. A threat actor infiltrated the network, exfiltrated PII (names, SSNs, driver's licenses, DOBs) between Feb 2-3, 2022, and demanded ransom. The company did not pay, engaged forensic investigators, notified law enforcement, and implemented MFA and enhanced security controls. 831 Washington residents were affected.
- South Carolina State AGas victim2022-04-14
AUTOPAY Direct, Inc. notified customers of a data breach where a threat actor infiltrated its network, exfiltrated PII (names, SSNs, driver's licenses, DOBs), and demanded ransom. The company did not pay, engaged forensic investigators, terminated access, and implemented MFA and enhanced security controls. Incident occurred Feb 2-3, 2022; notification sent Feb 5, 2022.
- Maine State AGas victim2022-04-14
AUTOPAY Direct, Inc. reported a data breach affecting 160,247 individuals, which was discovered on February 5, 2022. The incident, an external system breach, occurred on February 2, 2022. The compromised information included names and driver's license or non-driver identification card numbers. Affected individuals were notified on April 11, 2022.
- Indiana State AGas victim2022-04-11
AUTOPAY Direct, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-10-11 and was reported on 2022-04-11. 1,806 Indiana residents were affected. 160,247 individuals affected in total.
- Montana State AGas victim2022-03-31
AUTOPAY Direct, Inc. notified Montana residents of a ransomware incident where a threat actor infiltrated the network, exfiltrated PII (names, SSNs, driver's licenses, DOBs), and demanded ransom. The breach occurred from Oct 11, 2021, to Feb 5, 2022. AUTOPAY engaged forensic investigators, notified law enforcement, terminated access, and implemented MFA and enhanced security controls.
- Massachusetts State AGas victim2022-03-22
AUTOPAY Direct, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-03-22. 526 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2022-01-01
AUTOPAY DIRECT, INC filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-213). The register records the breach as discovered on February 5, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.