Data leak
β Supply Chain
BleepingComputer
Primary Source βIncident Details
Financial Business and Consumer Solutions (FBCS), a Pennsylvania-based debt collection agency, suffered a ransomware attack between February 14-26, 2024. The breach ultimately affected 4.2 million individuals. Downstream victims included customers of Comcast (273,703 customers), Truist Bank, and others β because FBCS had previously handled collections for these companies. FBCS initially told clients no customer data was involved, then had to retract this. Exposed data included names, addresses, Social Security numbers, dates of birth, and account numbers. FBCS’s worsening financial position forced downstream firms to conduct their own notification and remediation. The FCC later fined Comcast $1.5 million over the incident.
Technical Details
- Initial Attack Vector
- CWE-284: Improper Access Control
- Vendor / Product
- Financial Business and Consumer Solutions (FBCS) debt collection platform
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-02-14 Breach occurred
- 2024-04-26 Publicly disclosed
- 2024-10-07 Customers notified