[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZCvfgNxvI_pze7HDV98um6JF7T3I0eahqyiJZREc3k0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":19,"dataClasses":20,"description":27,"source":28,"isVerified":4,"isSpamList":29,"isSensitive":4,"severity":30,"processingStatus":31,"logoUrl":32,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a6711acbd79cec71f30b1fd","YouLendUS2026","YouLend US 2026 Data Breach","youlend-us-2026","youlend.com",{"name":12,"sector":13,"country":14,"website":10},"YouLend US LLC","Financial Services","United States","2026-06-05T00:00:00.000Z","2026-07-27T08:07:08.583Z","2026-07-27T09:30:00.000Z",0,null,[21,22,23,24,25,26],"Personal information","Names","Dates of birth","Social Security numbers","Financial account numbers","Credit or debit card numbers","\u003Cp>\u003Cstrong>The YouLend US 2026 data breach\u003C\u002Fstrong> involved unauthorized access to the computer network of an embedded business-finance provider and acquisition of certain files containing personal information. YouLend US LLC received alerts about a network disruption on June 9, 2026, and an investigation with outside cybersecurity specialists determined that unauthorized access occurred from June 5 through June 9.\u003C\u002Fp>\n\u003Cp>The official consumer letter dated July 15 directly confirms names, dates of birth, and Social Security numbers. A source based on regulatory filings reports that financial-account numbers or credit\u002Fdebit-card numbers were also involved for some people. The Texas record reports 2,793 residents, while the letter identifies an 89-person Rhode Island subset; because no nationwide total is known, pwnCount and totalRecords are zero.\u003C\u002Fp>\n\u003Ch2>How Was the YouLend US Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary evidence is YouLend US's consumer notice published through the California Attorney General breach record. On the company's behalf, the letter directly identifies the organization, network-alert date, four-day unauthorized-access period, file acquisition, person-specific data fields, law-enforcement notification, and protective services offered.\u003C\u002Fp>\n\u003Cp>A Texas Attorney General regulatory record supports the number of notified people in that state. Claim Depot links the California and Texas official disclosures and summarizes the event timeline, data classes, and 2,793-person Texas subset. The sources align on access dates, the finding that files were acquired, and core identity fields; LeakData does not treat general protection instructions as incident fields.\u003C\u002Fp>\n\u003Ch2>What Happened From June 5 Through June 9, 2026?\u003C\u002Fh2>\n\u003Cp>YouLend received alerts indicating a disruption to its computer network on June 9. The organization immediately began an investigation and engaged outside cybersecurity specialists. Their joint work found that the network was accessed without authorization from June 5 through June 9 and that certain files containing personal information were acquired during that window.\u003C\u002Fp>\n\u003Cp>The public letter does not identify the initial entry method, actor, ransom demand, malware, or technique used to maintain access. The statement that files were acquired confirms data copying but does not establish that the material was publicly released. LeakData records the confirmed acquisition without guessing undisclosed technical details.\u003C\u002Fp>\n\u003Ch2>What Identity Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The official sample letter tells its recipient that a name, date of birth, and Social Security number were involved. Together, those three fields create substantial risk of fraudulent credit applications, tax-identity misuse, abuse of account-verification processes, and targeted phishing. The same combination should not be assumed to have existed in every affected file.\u003C\u002Fp>\n\u003Cp>The protection appendix mentions addresses, driver's licenses, and other identity documents as general examples that may be required to request a credit freeze. That guidance does not confirm those fields were acquired in the incident. LeakData does not add an address, driver's license, passport, email, phone number, or login credential merely because it appears in protective instructions.\u003C\u002Fp>\n\u003Ch2>What Financial Information Was In Scope?\u003C\u002Fh2>\n\u003Cp>The source connecting the California and Texas filings lists financial-account numbers and credit or debit-card numbers among possible fields for some affected people. Those fields are consistent with the company's role in embedded business financing, but they were not present for every person, and the visible variable portion of the official sample letter identifies only name, birth date, and SSN.\u003C\u002Fp>\n\u003Cp>The public material does not specifically confirm a card expiration date, CVV, PIN, bank name, account-access password, or transaction history. LeakData keeps the financial category at the level stated by the source and does not add those subfields. Recipients should enable activity alerts with their financial institutions and closely review unfamiliar transactions or new accounts.\u003C\u002Fp>\n\u003Ch2>How Many People Were Affected and Was Misuse Observed?\u003C\u002Fh2>\n\u003Cp>The Texas regulatory disclosure reports 2,793 residents, and the state appendix to the sample letter identifies 89 Rhode Island residents. These are separate state subsets, not a deduplicated nationwide total. LeakData does not add them together and present the result as a U.S. total; pwnCount, totalRecords, and importedRecordCount are zero, with the subsets preserved in the source note.\u003C\u002Fp>\n\u003Cp>YouLend twice states that, as of the letter date, it had no evidence that personal information was misused for fraud or identity theft. That is a favorable but time-bound finding and does not eliminate future risk. Because file acquisition was confirmed and durable identifiers such as SSNs were involved, long-term monitoring may still be appropriate.\u003C\u002Fp>\n\u003Ch2>How Did YouLend Respond and How Can People Protect Themselves?\u003C\u002Fh2>\n\u003Cp>YouLend took steps to secure systems, reported the incident to federal law enforcement and other authorities, and offered 12 months of complimentary single-bureau credit monitoring, a credit report, credit score, and proactive fraud assistance through Cyberscout. A help line at 1-844-671-5730 was established from 8:00 a.m. to 8:00 p.m. Eastern on weekdays.\u003C\u002Fp>\n\u003Cp>Recipients should enroll only with the official code in their letter and review credit reports and financial accounts for unfamiliar inquiries, accounts, or transactions. If an SSN was involved, freezes at all three bureaus, a fraud alert, and an IRS Identity Protection PIN may be appropriate. SSNs or activation codes should not be shared in unexpected messages claiming to represent YouLend. LeakData does not host personal data.\u003C\u002Fp>","Official YouLend US consumer notice confirming unauthorized network access and acquisition of files containing personal information",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fyoulend_com.svg"]