October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Collection agency FBCS warns data breach impacts 1.9 million people

FBCS said unauthorized access to its network potentially affected 1,955,385 people. Here is the verified timeline, what information may be involved and the steps recipients should take.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Financial Business and Consumer Solutions, Inc. (FBCS), a third-party debt collector, reported a cybersecurity incident potentially affecting 1,955,385 people—about 1.9 million. FBCS said unauthorized access occurred from February 14 through February 26, 2024, and that it discovered the access on February 26. The affected environment was FBCS’s network; sample notices say the systems of client organizations were not breached.

What happened in the FBCS breach?

FBCS said its investigation found that an unauthorized actor could view or acquire information on its network during the February 14–26, 2024 access period. The company reported the incident to affected people after investigating which records and individuals were involved.

Date What it means
February 14, 2024 Beginning of the unauthorized-access period identified in FBCS’s investigation.
February 26, 2024 FBCS discovered the unauthorized access; its investigation identifies this as the end of the access period.
April 26, 2024 A Maine filing reported 1,955,385 potentially affected people nationwide.
Later in 2024 Additional state and client-specific notices, including California filings, appeared as notification work continued.

See the incident summary, the Maine notice record, and the California attorney general’s breach listing.

Who is FBCS, and why might you receive its letter?

Financial Business and Consumer Solutions is a third-party debt-collection company. It handles collection-related information for other organizations, which can include creditors, health-care providers, schools, banks and other businesses. You therefore may receive an FBCS-related notice even if you never knowingly contacted FBCS or do not recognize an unpaid debt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A notice does not by itself prove that you owe money. It indicates that information connected with an FBCS client may have been stored in FBCS’s environment.

How many people were affected?

The precise figure reported in a state filing was 1,955,385 individuals. “Nearly 2 million” and “1.9 million” are rounded descriptions. This is the number of people notified as potentially affected—not the number of confirmed identity-theft victims.

What information may have been exposed?

Public reporting identified Social Security numbers among the information involved. The categories differed by person and by the organization that supplied the data. Your individual notice is the authoritative source for the fields associated with you.

Do not assume that every recipient had every category below in the incident:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • name, address or date of birth;
  • Social Security number;
  • account, claim or collection information;
  • medical or insurance information; or
  • financial information.

Public notices describe information that may have been viewed or acquired. They do not establish that every listed field was taken for every person. A client-specific notice also states that not all listed information affected every individual; see the sample notice for that qualification.

Was my bank, hospital, school or creditor hacked?

The confirmed incident description concerns FBCS’s network environment. Sample notices say the relevant data owner’s own systems were not affected. A client’s information could have been present on FBCS systems without an intrusion into the client’s network. That distinction does not determine whether the client has other, unrelated incidents.

How can you tell whether you are affected?

  1. Find a mailed notice from FBCS or an FBCS client and check the date, sender and data-owner name.
  2. Read the section identifying the information associated with you; look specifically for a Social Security number or other sensitive category.
  3. Note the reference or enrollment code and any deadline for the complimentary service.
  4. Use the telephone number or web address printed in the letter, but independently verify the domain before entering personal information.
  5. If you received multiple letters, keep each one. Multiple notices can reflect more than one FBCS client or a supplemental notice and do not necessarily mean separate breaches.

A notice sent months after February 2024 is not necessarily suspicious: investigation and record matching can delay client-specific notification.

What should affected people do now?

1. Preserve and verify the notice

Save the letter, envelope, enrollment code, terms and deadline. Do not rely on an unsolicited email or text that asks for a Social Security number, bank password, payment-card details or a one-time authentication code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Decide whether to enroll in the complimentary service

FBCS sample notices identify CyEx as the provider of credit monitoring and identity-restoration assistance. Enrollment is not automatic. The reviewed sample generally offered 12 months, while some client-specific notices reference 24 months, so follow the duration and deadline in your own letter.

3. Freeze your credit files

If your Social Security number was involved, a security freeze is generally the strongest preventive measure against many new-credit applications. Place it separately with all three nationwide bureaus:

A freeze is free, but you may need to lift it temporarily when applying for credit. It does not stop takeovers of existing accounts, tax or benefit fraud, medical identity theft or social-engineering scams.

4. Review your credit reports

Obtain reports through the federally authorized AnnualCreditReport.com. Look for unfamiliar accounts, hard inquiries, collection accounts or address changes. Dispute errors with the bureau and the company that supplied the information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Monitor accounts and statements

Check bank, card, insurance, medical and other sensitive-account statements. If your notice mentions medical or debt data, review bills, explanation-of-benefits statements and collection correspondence—not just credit reports.

6. Secure online accounts

  • Change passwords reused on more than one service.
  • Use a unique password for each important account.
  • Turn on multifactor authentication, preferably with an authenticator app or security key where available.
  • Review account-recovery email addresses, phone numbers and login sessions.

7. Report suspected identity theft

Use the FTC’s recovery portal at IdentityTheft.gov if you find an unfamiliar account, tax filing, benefit claim or other evidence of misuse. Contact the affected institution through a verified number, not one supplied by a suspicious caller.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does the CyEx monitoring offer actually do?

Credit monitoring can alert you to certain new inquiries, accounts or changes after they occur. Identity-restoration services may provide assistance with documenting and resolving suspected theft. Neither service removes information from criminals’ possession, prevents every form of fraud or replaces a credit freeze.

Enrollment may be time-limited and requires your action. Save the confirmation email, service terms, start date and expiration date. The offer’s duration and covered features can vary by FBCS client notice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Could a follow-up message be a scam?

Data-breach notices often lead to convincing phishing attempts. Use only the enrollment instructions in your verified notice. Do not provide a Social Security number, bank login, one-time code or card number to someone claiming that a “free” service requires payment or urgent verification.

The breach also does not validate a later debt-collection call. Independently verify the creditor, amount and legal documentation before discussing a debt or making a payment, even if the caller knows personal details.

Is there a lawsuit or payout?

The breach and notification records cited here do not establish a current nationwide settlement, court judgment or guaranteed compensation program. Law-firm advertisements or “claim” pages are not proof that a case has merit or that money is available. Treat any payment claim as unverified unless a court, government agency or official settlement administrator provides the terms.

Free options versus paid identity protection

Start with the free measures: the FBCS/CyEx offer in your notice, a credit freeze, AnnualCreditReport.com and IdentityTheft.gov. Paid services such as Aura, Norton LifeLock and IdentityForce may appeal to people who want centralized alerts, family monitoring or restoration assistance. They are optional, do not prevent the FBCS exposure and should be compared for current introductory and renewal prices, cancellation terms, coverage and insurance limits before purchase.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

FBCS reported unauthorized access to its own network that potentially affected 1,955,385 people. Read your specific notice to identify the data involved, use the offered CyEx service if appropriate, and prioritize a three-bureau credit freeze, free credit reports and account monitoring—because monitoring detects some misuse but cannot prevent it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.