Cyber Incident Victim: Trusted Quid Ltd
Timeline
Summary
A Scottish short-term loan provider experienced unauthorized access to its website, resulting in the theft of applicant data submitted over an extended period. The breach compromised sensitive personal and financial details including names, contact information, dates of birth, addresses, income, employment status, loan specifics, and bank account information for approximately 65,000 individuals. Upon discovery, the organization promptly engaged law enforcement and regulatory authorities while confirming the incident exclusively affected customers who directly submitted loan applications through their platform.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Trusted Quid, a Scottish short-term loan provider, experienced a data breach involving unauthorized access to its website between July 1, 2016, and February 17, 2018. The breach specifically targeted data entered by individuals applying for loans through the Trusted Quid website during this 20-month period. The company discovered that attackers stole applicant information, prompting immediate notification to law enforcement and regulatory authorities upon identification of the incident. Trusted Quid publicly disclosed the breach through a press release on March 20, 2018, confirming the compromise of sensitive customer data while emphasizing that only website loan applicants were affected. The breach timeline indicates continuous unauthorized access for over nineteen months before detection and containment measures were implemented in February 2018. No technical details regarding the attack vector or intrusion methods were disclosed in the public notification.

The incident impacted up to 65,925 loan applicants whose personal and financial information was exposed. Compromised data included full names, phone numbers, dates of birth, physical addresses, income details, loan application specifics, employment information, and bank account credentials. Trusted Quid acknowledged the severity of the breach in their statement but did not disclose whether financial fraud or identity theft had occurred as a result. The company's response focused on regulatory compliance through prompt notifications rather than detailing technical remediation steps or security improvements implemented post-breach. Affected individuals were directed to review the full press release for additional resources, though no mention was made of credit monitoring services or direct victim support beyond informational guidance. The breach exposed significant vulnerabilities in Trusted Quid's web application security over an extended period without detection.
