Credit Control Corporation
ent_b8ddbc7430fe19b7fb3df93b
Disclosures
14
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
607,787
nationwide · HHS OCR VA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Credit Control Corporation
- Normalized
- credit control— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- creditcontrol.net
Disclosure history (14)newest first
- Vermont State AGas victim2026-06-13
Credit Control Corporation (CCC) notified consumers of a data security incident occurring March 2-7, 2023, discovered March 7, 2023. Unusual activity led to files being copied from CCC's network. Data potentially involved account holder names and financial account data. CCC engaged forensic specialists, isolated systems, notified law enforcement, and offered 1 year of credit monitoring via Kroll. No evidence of specific individual data copying, but possibility not ruled out.
- New Hampshire State AGas victim2023-08-23
R&B Credit Control Corporation reported a data security incident occurring between March 2-7, 2023. The company became aware of unusual activity on March 7, 2023, and determined files were copied from its network. The incident involved personal information including names, SSNs, and dates of birth. The company engaged forensic specialists, notified law enforcement, and offered credit monitoring services.
- Washington State AGas victim2023-08-23
R&B Corporation of Virginia d/b/a Credit Control Corporation (CCC) experienced a ransomware incident between March 2-7, 2023, discovered on March 7, 2023. Files containing names and SSNs were copied. CCC notified 1,564 Washington residents starting May 4, 2023, and offered credit monitoring. Federal law enforcement was notified.
- Vermont State AGas victim2023-08-23
R&B Corporation of Virginia (dba Credit Control Corporation) notified consumers of a data security incident occurring March 2-7, 2023. Unusual activity led to the copying of files containing account holder names and data elements. No evidence confirmed data theft, but it cannot be ruled out. The company engaged forensic specialists, notified law enforcement, and offered one year of credit monitoring via Kroll.
- Maine State AGas victim2023-08-23
R&B Corporation of Virginia d/b/a Credit Control Corporation reported a data breach to the Maine Attorney General, stating that an external system breach (hacking) occurred on March 2, 2023. The breach was discovered on May 3, 2023. The incident affected 22 Maine residents, compromising their names and Social Security numbers. The company began notifying affected individuals on May 15, 2023, and offered identity theft protection services.
- New Hampshire State AGas victim2023-06-20
R&B Credit Control Corporation (CCC) filed a supplemental notice with the New Hampshire Attorney General regarding a data security incident. Unauthorized access occurred between March 2-7, 2023, with discovery on March 7, 2023. Files were copied from the network. CCC notified federal law enforcement, isolated systems, and engaged forensic specialists. Notices were sent to business partners and individuals starting May 4, 2023. The notice covers 32 New Hampshire residents (16 initial, 16 supplemental). Data involved likely included names and government IDs. CCC offered 1 year of credit monitoring via Kroll.
- California State AGas victim2023-06-13
R&B Corporation of Virginia d/b/a Credit Control Corporation experienced a data security incident between March 2 and March 7, 2023. On March 7, 2023, the company detected unusual activity and isolated affected systems. An investigation determined that certain files containing account holder names were copied from the network. The company notified federal law enforcement, engaged forensic specialists, and implemented additional security measures and employee training. Affected individuals were offered one year of complimentary credit monitoring and identity protection services through Kroll.
- Oregon State AGas victim2023-06-13
Credit Control Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-13. The breach occurred during 3/2/2023 - 3/7/2023. The breach was discovered on 5/3/2023. 150,973 individuals were affected. Notice was sent on 5/15/20236/13/2023.
- Maine State AGas victim2023-06-13
R&B Corporation of Virginia d/b/a Credit Control Corporation ("CCC") experienced an external system breach on March 2, 2023, which was discovered on May 3, 2023. The breach affected 23 Maine residents, compromising their names and Social Security numbers. CCC provided written notification to the affected individuals on May 15, 2023, and June 13, 2023, and offered 12 months of credit monitoring and identity theft restoration services through Kroll.
- New Hampshire State AGas victim2023-05-19
R&B Credit Control Corporation (CCC) reported a data event where unauthorized access occurred between March 2-7, 2023. CCC discovered the incident on March 7, 2023, and determined files were copied. The breach affected 16 New Hampshire residents, exposing personal information including names and government IDs. CCC engaged forensic specialists, notified law enforcement, and provided credit monitoring services.
- Maine State AGas victim2023-05-15
R&B Corporation of Virginia, doing business as Credit Control Corporation (CCC), experienced an external system breach on March 2, 2023, which was discovered on May 3, 2023. The breach affected 286,699 individuals in total, including 20 residents of Maine. The compromised information includes names and Social Security numbers. CCC began notifying affected consumers on May 15, 2023, and is offering 12 months of identity theft protection services through Kroll.
- Montana State AGas victim2023-05-15
Credit Control Corporation (CCC) notified individuals of a cyber incident occurring March 2-7, 2023, discovered March 7, 2023. Files were copied from CCC's network. Data involved likely included names and government IDs. CCC engaged forensic specialists, isolated systems, notified law enforcement, and offered 1 year of Kroll identity monitoring. Notification began May 4, 2023.
- VIRGINIAHHS OCRas victim2023-05-13
R&B Corporation of Virginia d/b/a Credit Control Corporation reported to HHS on 2023-05-13 a Hacking/IT Incident affecting 607,787 individuals. Breached information located on Network Server. The incident involved names, SSNs, addresses, and claims/financial data. The entity provided credit monitoring and implemented safeguards.
- Illinois State AGas victim2023-01-01
R&B CREDIT CONTROL CORP. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-583). The register records the breach as discovered on May 4, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.