Data breach at US debt collector exposes over a million users

An abstract image of a magnifying glass over a digital cloud.
(Image credit: Shutterstock/Illus_man)

NCB Management Services, a debt collecting company from the United States, has suffered what appears to be a ransomware attack in early February 2023 that left the data of over a million people exposed.

Based on breach notification letters sent to affected parties, as well as the filing it submitted with the Maine Attorney General, some 1.1 million people were affected by the breach.

“Recently, confidential client account information maintained by NCB was accessed by an unauthorized party. To date, we are unaware of any misuse of your information as a result of this incident,” NCB said in the letter to its users. 

Paying the ransom

It took the company some three days to realize they had been breached. From that point, until April 19, NCB was engaged in forensic analysis, trying to understand which types of data were accessed. It later learned that the attackers stole financial account numbers or payment card numbers “in combination with security code, access code, password or PIN for the account.”

The company also hints that it paid the ransom, as it stated that it “obtained assurances that the unauthorized third party no longer has access to any of NCB’s data.”

Regardless, NCB said it will provide its users with up to two years of free identity theft monitoring services.

“In addition to activating the complimentary services offered, we recommend you review your credit reports and account statements over the next 12 to 24 months and notify your financial institution of any unauthorized transactions or incidents of suspected identity theft,” NCB said.

Cybercriminals usually steal sensitive data in order to sell it on the black market, or use it to run phishing campaigns, identity theft, wire fraud, and other forms of cybercrime. Companies are urged not to pay the ransom demand, as there are no guarantees they’ll remain safe, or get their data back. The only thing they can be sure of is that they’ll fund another round of cybercrime. 

Via: Cybernews

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Data Breach
US state sues T-Mobile over 2021 data breach which leaked data of millions
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Data breach
Top medical billing firm says data breach hit 360,000 users
Security
American National Insurance Company breach data found online
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)