The Maine Office of the Attorney General disclosed a data breach affecting AvidXchange, Inc. between March 2 and April 27, 2023, reported on December 10, 2023. The incident involved unauthorized access to personal information, specifically financial account numbers, impacting 204 individuals, including 2 Maine residents. The breach exposed sensitive financial data, posing risks such as identity theft and fraud. In response, AvidXchange is providing 12 months of identity theft protection services via IDX to affected individuals. The nature of the compromised data financial account details suggests potential misuse for fraudulent transactions or financial exploitation. While the breach did not result in immediate public disruptions (e.g., operational outages or ransom demands), the exposure of financial records aligns with scenarios where customer data integrity is compromised, warranting heightened monitoring and mitigation measures. The company’s proactive offer of identity protection reflects an acknowledgment of the seriousness of the data exposure and its potential downstream consequences for affected parties.
TPRM report: https://www.rankiteo.com/company/avidxchange-inc-
"id": "avi309091725",
"linkid": "avidxchange-inc-",
"type": "Breach",
"date": "3/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 204,
'industry': 'Financial Technology (FinTech)',
'location': 'Charlotte, North Carolina, USA',
'name': 'AvidXchange, Inc.',
'type': 'Corporation'},
{'customers_affected': 2,
'industry': 'Legal/Regulatory',
'location': 'Maine, USA',
'name': 'Maine Office of the Attorney General',
'type': 'Government'}],
'customer_advisories': '12 months of identity theft protection services '
'offered through IDX',
'data_breach': {'number_of_records_exposed': 204,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['personal information',
'financial account numbers']},
'date_publicly_disclosed': '2023-12-10',
'description': 'The Maine Office of the Attorney General reported a data '
'breach involving AvidXchange, Inc. on December 10, 2023. The '
'breach occurred between March 2, 2023 and April 27, 2023, '
'affecting 204 individuals, including 2 residents of Maine, '
'involving unauthorized access to personal information '
'including financial account numbers. AvidXchange is offering '
'12 months of identity theft protection services through IDX.',
'impact': {'data_compromised': ['personal information',
'financial account numbers'],
'identity_theft_risk': 'High (identity theft protection services '
'offered)',
'payment_information_risk': 'High (financial account numbers '
'exposed)'},
'references': [{'date_accessed': '2023-12-10',
'source': 'Maine Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
'Attorney General'},
'response': {'communication_strategy': 'Public disclosure via Maine Office of '
'the Attorney General; offering '
'identity theft protection to affected '
'individuals',
'third_party_assistance': 'IDX (identity theft protection '
'services)'},
'title': 'AvidXchange Data Breach (2023)',
'type': 'Data Breach'}