Confirmed breach. Intrusion Mar 2, 2023–Mar 7, 2023, discovered Mar 7, 2023 — the first regulatory filing landed 67 days later (flagged late). 607,787 individuals reported across the linked filings.
Regulatory clocksMaine✗ ME AG >90d · 112dWashington✗ WA AG >90dHIPAA✓ HHS notifiedCalifornia✓ CA 60-day OK · 58dOregon✓ OR AG ≤45dFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Affected (total reported)
102days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
607,787
Data types
2
Identity (basic) · Government ID
Jurisdictions
6
CA ME MT OR VA WA
Linked filings
8
HHS OCR · State AG
Sensitive data
identity_government
Affected residents by state
per-filing reported counts
OR150,973
WA1,564
MT269
ME23
ME22
ME20
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
8 filings across 6 jurisdictions · May 13, 2023 – Aug 23, 2023 · 3 milestones
Breach window
Mar 2, 2023
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Mar 7, 2023
Reported by CALIFORNIA AG, WASHINGTON AG filings
57 days
Breach discoveredconflicts with Mar 7, 2023AG web form
May 3, 2023
Reported by MAINE AG, OREGON AG filings
🇺🇸VAHHS OCRFirst filinglinked via same-victim cross-source · 100%
R&B Corporation of Virginia d/b/a Credit Control Corporation reported to HHS on 2023-05-13 a Hacking/IT Incident affecting 607,787 individuals. Breached information located on Network Server. The incident involved names, SSNs, addresses, and claims/financial data. The entity provided credit monitoring and implemented safeguards.
Affected (this filing): 607,787
5 State AG filingsMay 15, 2023 – Jun 13, 2023ExpandCollapse
R&B Corporation of Virginia d/b/a Credit Control Corporation, a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-03-07 and filed notice on 2023-08-23. 1,564 Washington residents were affected. 169 days elapsed between awareness and notification. 5 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 1,564
🦞Maine State AGMost recentlinked via multistate filing link · 95%
R&B Corporation of Virginia d/b/a Credit Control Corporation reported a data breach to the Maine Attorney General, stating that an external system breach (hacking) occurred on March 2, 2023. The breach was discovered on May 3, 2023. The incident affected 22 Maine residents, compromising their names and Social Security numbers. The company began notifying affected individuals on May 15, 2023, and offered identity theft protection services.
Affected (this filing): 22
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
HHS notified
bd_5e0a9abf83df9e95
R&B Corporation of Virginia, doing business as Credit Control Corporation (CCC), experienced an external system breach on March 2, 2023, which was discovered on May 3, 2023. The breach affected 286,699 individuals in total, including 20 residents of Maine. The compromised information includes names and Social Security numbers. CCC began notifying affected consumers on May 15, 2023, and is offering 12 months of identity theft protection services through Kroll.
Affected (this filing): 20
ME AG ≤30d · 12d
🦬Montana State AGlinked via multistate filing link · 95%
R&B Credit Control Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2023-05-15. The breach occurred from 3/2/2023 to 3/7/2023. 269 Montana residents were affected.
Affected (this filing): 269
🐻California State AGlinked via multistate filing link · 95%
R&B Corporation of Virginia d/b/a Credit Control Corporation experienced a data security incident between March 2 and March 7, 2023. On March 7, 2023, the company detected unusual activity and isolated affected systems. An investigation determined that certain files containing account holder names were copied from the network. The company notified federal law enforcement, engaged forensic specialists, and implemented additional security measures and employee training. Affected individuals were offered one year of complimentary credit monitoring and identity protection services through Kroll.
CA 60-day OK · 58d
🦫Oregon State AGlinked via multistate filing link · 95%
Credit Control Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-13. The breach occurred during 3/2/2023 - 3/7/2023. The breach was discovered on 5/3/2023. 150,973 individuals were affected. Notice was sent on 5/15/20236/13/2023.
Affected (this filing): 150,973
OR AG ≤45d
🦞Maine State AGlinked via multistate filing link · 95%
R&B Corporation of Virginia d/b/a Credit Control Corporation ("CCC") experienced an external system breach on March 2, 2023, which was discovered on May 3, 2023. The breach affected 23 Maine residents, compromising their names and Social Security numbers. CCC provided written notification to the affected individuals on May 15, 2023, and June 13, 2023, and offered 12 months of credit monitoring and identity theft restoration services through Kroll.