Progressive Leasing discloses cyberattack that exposed Social Security numbers
- Organization
- Progressive Leasing
- Exploit
- Ransomware
- Industry
- Consumer Leasing
PROG Holdings told the U.S. Securities and Exchange Commission on September 21, 2023 that its Progressive Leasing subsidiary had suffered a cybersecurity incident affecting certain of its systems. The Salt Lake City lease-to-own provider said preliminary findings indicated the involved data contained a substantial amount of personally identifiable information, including Social Security numbers, belonging to customers and other individuals.
Progressive Leasing said it engaged third-party cybersecurity experts, notified law enforcement and began remediation immediately after detecting the intrusion. The company reported no major operational impact on its services and said its sibling subsidiaries were unaffected, while warning it expected to incur significant response and remediation costs.
The ALPHV/BlackCat ransomware group claimed responsibility, adding Progressive Leasing to its leak site and asserting it held personal data on more than 40 million customers. That figure was never substantiated. Progressive Leasing subsequently reported that the incident affected 193,055 people, and that the intruder first gained access on September 9, 2023 and was detected on September 11.
Notification letters went out in late October 2023. According to ClassAction.org, the exposed fields included names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers and financial information such as bank account, income and credit details. Consolidated class action litigation followed and was later settled for $3.25 million.