2023 AvidXchange — unauthorized network access; consumer PII exfiltration (~6.5k individuals)
Data compromised
Name, SSN, financial account identifiers, payment card data, and password fields per regulator-facing letters
Technical writeup
AvidXchange detected suspicious activity on April 3, 2023, during monitoring of its corporate network. Forensics concluded an unauthorized actor removed files containing consumer confidential information; state regulatory summaries (e.g., Massachusetts breach index, Maine AG postings) cited on the order of 6,495 affected people with combinations of name, Social Security number, financial account and payment-card data, and related credentials in some templates. The company notified in October 2023 and offered credit monitoring; reporting often distinguished this event from the firm’s GoAnywhere-related supply-chain exposure.
Root cause
Criminal intrusion into corporate IT with data staging/exfiltration (detailed TTP not fully public)