A disruption to YouLend US’s internal network led the company to discover a four-day intrusion that exposed personal and financial information, state filings show.
The Atlanta-based financial technology company received alerts about the disruption June 9 and brought in outside cybersecurity specialists. Investigators determined an unauthorized party had accessed its network from June 5 through June 9 and acquired certain files.
YouLend provides embedded financing to small and midsize businesses through commerce, software and payment-platform partners. The company has not identified the internal systems that were disrupted or said whether financing, payment processing or partner integrations were interrupted.
The public record limits the confirmed disruption to YouLend’s internal network. The company has not disclosed how long systems were impaired, whether employees used workarounds or when normal internal operations were fully restored.
A Texas attorney general record published Sept. 3 lists 2,826 Texans as affected. The regulator said the compromised information included names, Social Security numbers, financial information and other data.
An earlier notice filed with the California attorney general identified names, dates of birth and Social Security numbers among the affected information. Teiss reported that a supplemental New Hampshire filing also listed financial-account and payment-card information.
YouLend said it secured its systems, notified federal law enforcement and other authorities, and offered affected people 12 months of credit monitoring and identity-protection services.
The company has not said how the intruder entered its network. No known threat actor has claimed responsibility, according to Teiss, and YouLend has not disclosed receiving a ransom demand.
YouLend has not released a detailed restoration timeline or final technical all-clear. No subsequent public notice reviewed by DysruptionHub described disruption continuing after June 9.