NCB Management breach grows past 1.5 million, starting with Bank of America customers
- Organization
- NCB Management Services
- Exploit
- Hacking
- Industry
- Debt Collection
NCB Management Services, a Pennsylvania accounts receivable and debt buying firm, began notifying consumers in late March 2023 that their personal information had been taken in a cyberattack. The company said an unauthorized party reached its systems on 1 February 2023 and that it detected the intrusion three days later, on 4 February. Confirmation that data had actually been removed came on 8 March.
The records involved related to Bank of America credit card accounts that NCB had purchased and that were already closed at the time of the attack. NCB stated that Bank of America's own systems were not compromised.
Reported figures were close but not identical. The Record put the number of affected people at 494,969, while SecurityWeek and other coverage of the notification described roughly 500,000. That was only the first tranche. The Record reported in June 2023 that NCB had notified more than a million further people, taking the total past 1.5 million and adding customers of Capital One, Pathward National Association and Exeter Finance. The exposed fields included names, addresses, telephone numbers, email addresses, dates of birth, driver's licence numbers, Social Security numbers and employment details, alongside financial data such as pay amounts, credit card numbers, routing numbers, account numbers, balances and account statuses.
NCB said the unauthorized activity on its systems had been stopped and that it had obtained assurances the third party no longer held any of the information, wording that several outlets read as a possible indication of a ransom payment. The company said it was not aware of the data being distributed or misused. Bank of America offered affected customers two years of identity theft protection through Experian, and federal law enforcement was investigating.