Clustered 6 filings across 6 jurisdictions · filing window Mar 31, 2022 → Apr 26, 2022. View entity profile → Other incidents for this victim →
incident inc_e13d749fa0474a52 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA ME MT NH SC WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Oct 11, 2021
When the intrusion reportedly occurred, per the linked filings
Feb 5, 2022
Reported by WASHINGTON AG, MAINE AG, CALIFORNIA AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
AUTOPAY Direct, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2022-03-31. The breach occurred from 10/11/2021 to 2/5/2022. 37 Montana residents were affected.
Affected (this filing): 37
AUTOPAY Direct, Inc., a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-02-05 and filed notice on 2022-04-14. 831 Washington residents were affected. 68 days elapsed between awareness and notification. 3 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 831
State AG breach notification from South Carolina regarding AUTOPAY Direct, Inc. The attached PDF content is empty or unreadable, preventing extraction of breach details, dates, or affected data types.
AUTOPAY Direct, Inc. reported a data breach affecting 160,247 individuals, which was discovered on February 5, 2022. The incident, an external system breach, occurred on February 2, 2022. The compromised information included names and driver's license or non-driver identification card numbers. Affected individuals were notified on April 11, 2022.
Affected (this filing): 160,247
AUTOPAY Direct, Inc. filed a New Hampshire security breach notification dated April 18, 2022. The incident impacted 62 New Hampshire residents. The company began notifying affected individuals and completed notifications during the week of April 18, 2022. Specific details regarding the attack vector or data types were not provided in the filing.
Affected (this filing): 62
AUTOPAY Direct, Inc. disclosed a ransomware incident in February 2022 where a threat actor infiltrated its network, exfiltrated PII, and demanded ransom. The company did not pay, engaged forensic investigators, and notified law enforcement. Affected individuals were offered 12 months of credit monitoring.