Charlottesville Settlement Company
ent_fc82eff10fedde0d
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
22,041
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Charlottesville Settlement Company
- Normalized
- charlottesville settlement— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- New Hampshire State AGas victim2026-03-18
Charlottesville Settlement Company (CSC) notified the New Hampshire Attorney General of a data security incident affecting 22 NH residents. An unknown actor gained unauthorized access to CSC's network on September 2, 2025. CSC discovered unusual activity on September 4, 2025, and confirmed on March 10, 2026, that personal information (names, SSNs, driver's license numbers) may have been accessed. CSC engaged forensic experts, hardened its environment, and provided 12 months of credit monitoring and identity protection services to affected individuals.
- Maine State AGas victim2026-03-18
Charlottesville Settlement Company experienced an external system breach (hacking) on September 2, 2025. The incident was discovered on September 4, 2025. The breach potentially affected the personal information of 22,041 individuals, including 19 Maine residents. Affected data likely included names and government identifiers. The company engaged external cybersecurity experts, secured its environment, and offered 12 months of credit monitoring and identity theft protection services to affected individuals.
- Massachusetts State AGas victim2026-03-18
Charlottesville Settlement Company notified Massachusetts residents of a data security incident affecting personal information, including Social Security Numbers. The company offered 24 months of credit monitoring via IDX. The notice does not specify the cause, date of discovery, or number of affected individuals.
- Vermont State AGas victim2026-03-18
Charlottesville Settlement Company (CSC) notified consumers of a data security incident where an unknown actor gained unauthorized access to its network on September 2, 2025. CSC discovered unusual activity on September 4, 2025. The incident may have exposed names and other personal information. CSC engaged external cybersecurity experts, secured its email environment, and is offering 12 or 24 months of complimentary credit monitoring and identity theft protection through IDX.
- Indiana State AGas victim2026-03-18
Charlottesville Settlement Company reported a data breach to the Indiana Attorney General. The breach occurred on 2025-09-02 and was reported on 2026-03-18. 30 Indiana residents were affected. 22,041 individuals affected in total.
- Nebraska State AGas victim2026-03-18
Charlottesville Settlement Company (CSC) notified Nebraska residents of a data security incident. CSC observed unusual activity on September 4, 2025, discovering unauthorized access occurred on September 2, 2025. CSC determined on March 10, 2026, that personal information (names and variable data elements) of some individuals was potentially accessed. CSC offered complimentary credit monitoring and identity theft protection services through IDX. CSC states there is no evidence of misuse of the information.