Data leak β›“ Supply Chain

BleepingComputer

πŸ“… 2024-02-14 🏒 Financial Business and Consumer Solutions (FBCS) debt collection platform
Primary Source β†—

Incident Details

Financial Business and Consumer Solutions (FBCS), a Pennsylvania-based debt collection agency, suffered a ransomware attack between February 14-26, 2024. The breach ultimately affected 4.2 million individuals. Downstream victims included customers of Comcast (273,703 customers), Truist Bank, and others β€” because FBCS had previously handled collections for these companies. FBCS initially told clients no customer data was involved, then had to retract this. Exposed data included names, addresses, Social Security numbers, dates of birth, and account numbers. FBCS’s worsening financial position forced downstream firms to conduct their own notification and remediation. The FCC later fined Comcast $1.5 million over the incident.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control
Vendor / Product
Financial Business and Consumer Solutions (FBCS) debt collection platform
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-02-14 Breach occurred
  2. 2024-04-26 Publicly disclosed
  3. 2024-10-07 Customers notified