Debt Collector Massive Data Breach

  • +3
    BigA
    | 3 replies
    Well known criminal outfit around here that regularly ignores all Federal and State Collection Laws and now this:

    https://www.foxnews.com/tech/massive-data-bre ... -cybercriminals

    Massive data breach exposes over 3 million Americans' personal information to cybercriminals
    The FBCS data breach has put sensitive data in the hands of crooks
    By Kurt Knutsson, CyberGuy Report Fox News
    Published June 22, 2024 10:00am EDT

    A debt collection enterprise called Financial Business and Consumer Solutions (FBCS) has been impacted by a massive data breach that affects millions of Americans. FBCS is a debt collection agency that specializes in recovering charged-off consumer and commercial debts, such as car loans, health care bills, utility bills, student loans and credit cards.
    The initial tally of those affected was around 1.9 million, which the company raised to 3 million in June 2024. The data breach leaked a treasure trove of consumer data, including full name, Social Security number (SSN), date of birth, and driver’s license number or ID card. The company has informed affected individuals as well as concerned authorities.
    What happened?
    According to a data breach notification sample the firm shared with the authorities, threat actors accessed FBCS' systems on Valentine's Day, but the company didn't realize the breach had occurred until Feb. 26. FBCS describes the incident as "unauthorized access to certain systems in its network."
    What’s concerning is that FBCS didn’t send the notification of the data breach until late April. "This notification was not delayed as a result of a law enforcement investigation," the company says, maintaining it was conducting its own probe while notifying federal authorities.
    The notification indicates that leaked information could include a variety of personal details, such as names, addresses, dates of birth, Social Security numbers, driver's licenses, state IDs, medical claim information, and even medical records. However, FBCS clarifies that not everyone affected will have all of this data exposed.

    What is FBCS doing about the data breach?
    FBCS is taking several steps to make things right. "Upon discovering this incident, we immediately took steps to conduct a diligent investigation to confirm the nature and scope of the incident. As part of FBCS’s ongoing commitment to the security of information on our platform, we also implemented additional safeguards in a newly built environment," the company said in the notification.
    The company is also providing affected individuals a free 24-month credit monitoring and identity restoration service. This data breach may make you more susceptible to phishing, identity theft, and other social engineering attacks. To protect yourself, be careful about what information you share and closely monitor your bank account activity for any suspicious transactions.
    We reached out to FBCS for a comment on this article but did not hear back by our deadline.

    6 measures to take to protect yourself from a data breach
    If you’ve been impacted by this data breach, follow these steps to protect your personal data and privacy.
    1) Invest in identity theft protection: If you think your personal data has been leaked, scammers may try to impersonate you to gain access to your private information. The best thing you can do to protect yourself from this type of fraud is to subscribe to an identity theft service. If you’re eligible, take the free CyEx subscription FBCS is offering.
    Identity theft companies can monitor personal information like your Social Security number (SSN), phone number and email address and alert you if it is being sold on the dark web or being used to open an account.  They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.
    2) Place a fraud alert: If you suspect you are a victim, contact the three major credit reporting agencies (Equifax, Experian or TransUnion) and request a fraud alert to be placed on your credit file. This will make it more difficult for identity thieves to open new accounts in your name without verification.
    3) Be cautious of phishing attempts: Be vigilant about emails, phone calls or messages from unknown sources asking for personal information. Avoid clicking on suspicious links or providing sensitive details unless you can verify the legitimacy of the request.
    The best way to protect yourself from clicking malicious links that install malware that may get access to your private information is to have antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams.
    4) Check Social Security benefits: It is crucial to periodically check your Social Security benefits to ensure they have not been tampered with or altered in any way, safeguarding your financial security and preventing potential fraud.
    5) Invest in personal data removal services: While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Remove your personal data from the internet with my top picks here.
    6) Change your password: You can render a stolen password useless to thieves simply by changing it. Opt for a strong password – one you don’t use elsewhere. Even better, consider letting a password manager generate one for you.
    Kurt’s key takeaway
    Data breaches and cyberattacks in the U.S. are on the rise. Companies are responsible for protecting customer data, and the least they can do is inform impacted individuals promptly when a cyberattack occurs. FBCS delayed the notification, which might have given attackers time to target unprepared individuals. If you think your data has been compromised, it's best to take a proactive approach. Start by changing your passwords and monitoring your bank accounts for unknown transactions.
    Copyright 2024 CyberGuy.com. All rights reserved.
  • +3
    B-Edwards replies to BigA
    The tips about Data Breaches are useful. Good to keep that info in mind. Thanks for the post.
  • +1
    Mosquito
    These data breaches at debt collectors are becoming common, which is no surprise considering the inadequate regulation and low standards in this industry. The FBCS breach is among the worst because of the large number of people impacted and because that number keeps growing.

    For those keeping score, here are some other major breaches at collectors:

    * Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency (AMCA), Aug. 2018-March 2019, up to 21 million individuals affected. AMCA filed Chapter 11 to avoid liability.

    * Receivables Performance Management (RPM), April 2021 (not disclosed until Nov. 2022!), 3.7 million individuals. RPM is facing a large class action but appears to have shut down.

    * Professional Finance Company (PFC), Feb. 2022, 1.9 million individuals. Class action settlement pending approval, Rodriguez et al. v. Professional Finance Company.

    * Convergent Outsourcing, Jun. 2022, 640,000 individuals. Convergent agreed to pay $2.45 million in a class action for this breach, on top of previous large settlements for violating TCPA and other consumer laws. Convergent has since been merged into TransWorld Systems.

    * NCB Management Services, Feb. 2023, 1.1 million individuals. Litigation active.

    * LCS Financial Services, Feb. 2023 (but not reported until Sep. 2023), total numbers not available but likely tens of thousands of individuals. Litigation active.

    * R&B Corporation d/b/a Credit Control Corporation (CCC), March 2023, 345,000 individuals. Litigation active.
  • +2
    Mike replies to BigA
    | 1 reply
    I wasn't aware of this and as I have received communication from them in the past on an alleged old debt, I believe I would be a victim to this.  Thank you for posting.
  • +2
    BigA replies to Mike
    I'm in the same boat.  Unfortunately I couldn't get enough evidence of their violations of the FDCPA to sue them otherwise I would have.
  • post pending moderator approval

Reply to topic