Progressive Leasing

Progressive Leasing

Progressive Leasing, a financial services provider, suffered a **data breach** on **September 9, 2023**, caused by **external system hacking**, which was detected two days later. The incident exposed sensitive personal information of **193,055 individuals**, including **Social Security numbers (SSNs)**—a high-value target for identity theft and fraud. The breach was publicly disclosed on **October 23, 2023**, with the company offering **12 months of complimentary credit monitoring and identity theft protection** to affected individuals as a remedial measure. The compromise of SSNs poses severe long-term risks, including financial fraud, unauthorized credit applications, and potential misuse of personal identities. Given the scale and sensitivity of the exposed data, the breach undermines customer trust and may lead to regulatory scrutiny, legal liabilities, and reputational damage. The attack’s focus on **personally identifiable information (PII)**—without evidence of ransomware—highlights a deliberate effort to exploit valuable data for malicious purposes, amplifying the severity of the incident.

Source: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/84f4c920-079d-4928-896e-977e2bd8ac35.shtml

TPRM report: https://www.rankiteo.com/company/progressive-leasing

"id": "pro731082025",
"linkid": "progressive-leasing",
"type": "Breach",
"date": "9/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 193055,
                        'industry': 'Financial Services / Leasing',
                        'name': 'Progressive Leasing',
                        'type': 'Company'}],
 'attack_vector': 'External System Hacking',
 'customer_advisories': 'Breach notification issued with offer of credit '
                        'monitoring and identity theft protection',
 'data_breach': {'data_exfiltration': 'Likely (given nature of breach)',
                 'number_of_records_exposed': 193055,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High (includes Social Security '
                                        'numbers)',
                 'type_of_data_compromised': ['Social Security numbers']},
 'date_detected': '2023-09-11',
 'date_publicly_disclosed': '2023-10-23',
 'description': 'The Maine Office of the Attorney General reported that '
                'Progressive Leasing experienced a data breach due to external '
                'system hacking. Approximately 193,055 individuals were '
                'affected, with Social Security numbers among the compromised '
                'information. Complimentary 12-month credit monitoring and '
                'identity theft protection services were offered to those '
                'affected.',
 'impact': {'brand_reputation_impact': 'Potential negative impact due to '
                                       'exposure of sensitive personal data',
            'data_compromised': ['Social Security numbers'],
            'identity_theft_risk': 'High (due to exposure of Social Security '
                                   'numbers)'},
 'investigation_status': 'Disclosed; remediation (credit monitoring) offered',
 'references': [{'source': 'Maine Office of the Attorney General'}],
 'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
                                                       'Attorney General '
                                                       'notified'},
 'response': {'communication_strategy': 'Public breach notification issued on '
                                        '2023-10-23',
              'incident_response_plan_activated': 'Likely (given notification '
                                                  'and remediation steps)',
              'recovery_measures': 'Offered 12-month complimentary credit '
                                   'monitoring and identity theft protection '
                                   'services to affected individuals'},
 'title': 'Progressive Leasing Data Breach (2023)',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.