Receivables Performance Management, LLC
ent_f27d75c360a08b585a1ba835
Disclosures
9
State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,766,573
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Receivables Performance Management, LLC
- Normalized
- receivables performance management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- receivablesperformance.com
Disclosure history (9)newest first
- Montana State AGas victim2022-11-21
Receivables Performance Management, LLC notified Montana residents of a ransomware incident. First access occurred April 8, 2021; ransomware launched May 12, 2021. The breach may have exposed Social Security numbers. RPM engaged forensic investigators, rebuilt servers, and offered TransUnion credit monitoring.
- California State AGas victim2022-11-21
Receivables Performance Management LLC experienced a ransomware attack. Unauthorized access began on April 8, 2021, and ransomware was launched on May 12, 2021, when the company became aware of the incident. The attack impacted server infrastructure, leading to systems being taken offline. Forensic investigation confirmed the presence of personal information, including Social Security numbers, in the affected files. The company disconnected equipment, rebuilt servers, and retained forensic investigators. Free credit monitoring is being offered to affected individuals.
- Indiana State AGas victim2022-11-21
Receivables Performance Management LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2021-04-08 and was reported on 2022-11-21. 72,183 Indiana residents were affected. 3,766,573 individuals affected in total.
- Hawaii State AGas victim2022-11-21
Receivables Performance Management (RPM) disclosed a ransomware incident where first access occurred April 8, 2021, and ransomware launched May 12, 2021. RPM identified Social Security numbers among compromised data. RPM disconnected equipment, rebuilt servers, retained forensic investigators, and offered TransUnion credit monitoring. Investigation concluded October 2022.
- Delaware State AGas victim2022-11-21
Receivables Performance Management LLC (RPM) disclosed a ransomware incident affecting its server infrastructure. First access occurred approx. April 8, 2021; ransomware launched May 12, 2021. RPM took systems offline, rebuilt servers, and retained forensic investigators. The investigation identified Social Security numbers in affected files. RPM offered TransUnion credit monitoring. Notification sent Dec 2022.
- Oregon State AGas victim2022-11-21
Receivables Performance Management LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2022-11-21. The breach occurred during 4/8/2021 - 5/12/2022. The breach was discovered on 10/2/2022. 3,766,573 individuals were affected. Notice was sent on 11/21/2022.
- Maine State AGas victim2022-11-21
Receivables Performance Management LLC reported an external system breach (hacking) occurring on April 8, 2021, discovered on October 2, 2022. The incident compromised names and Social Security Numbers of approximately 3.77 million individuals, including 8,682 Maine residents. The company provided written notification and offered 12 months of credit monitoring through TransUnion.
- Washington State AGas victim2022-11-21
Receivables Performance Management LLC reported a ransomware incident affecting Washington residents. First access occurred April 8, 2021; ransomware launched May 12, 2021. The breach compromised personal information including Social Security numbers for 48,252 individuals. RPM engaged forensic investigators, rebuilt servers, and offered credit monitoring.
- Delaware State AGas victim2022-10-02
Receivables Performance Management, LLC disclosed a ransomware incident affecting its server infrastructure. First access occurred April 8, 2021, with ransomware deployment on May 12, 2021. The incident resulted in unauthorized access and potential acquisition of personal information, including Social Security numbers. RPM physically disconnected equipment, rebuilt servers, retained forensic investigators, and offered 12 months of TransUnion credit monitoring. The notification was issued in December 2022.