A Pennsylvania-based debt collector that initially reported a data breach back in April that impacted 2 million individuals has filed an updated notice that reveals the number of impacted consumers is more than double that amount and that their medical information was among the information that was compromised.
This most recent notification from Financial Business and Consumer Solutions is the fourth time the collector has updated the size of the breach with the Maine Attorney General’s office, which maintains a database of hacks, breaches, and malware attacks.
Key updates:
- Total number of individuals affected: More than 4 million (up from 1.9 million)
- Types of data: Now includes medical information
- Breach timeline: Unauthorized access occurred between February 14-26, 2024
- HIPAA impact: Reported to the Department of Health and Human Services as affecting 209,000 individuals
FBCS has not provided specifics on the types of medical information exposed. The company is offering 12 months of free identity and credit monitoring to affected individuals.
What Happened: Back on February 26, the company — FBCS — discovered unauthorized access to certain systems in its network. The company launched an investigation and hired a forensic specialist to discover the full scope of what happened. The investigation revealed that the company’s systems were subject to unauthorized access between February 14 and February 26 and whomever had the unauthorized access had the ability to view or acquire certain information on the company’s network.
.




