Morningstar The Credit Pros Data Breach Exposes Sensitive Personal Information
Article Content
- •The Credit Pros experienced a data breach on June 16, 2026, affecting sensitive personal information.
- •The breach was claimed by a threat actor named Icarus, targeting the company's Salesforce environment.
- •Edelson Lechtzin LLP is investigating potential legal actions for those impacted by the breach.
On June 16, 2026, The Credit Pros reported a data breach involving its Salesforce environment, attributed to a threat actor named Icarus. The breach potentially compromised sensitive information, including names, dates of birth, addresses, credit/debit card numbers, Social Security numbers, and bank account details. Individuals affected by the breach may face increased risks of identity theft and fraud. Edelson Lechtzin LLP has initiated an investigation and is offering free case evaluations for those impacted. The firm is considering a class action lawsuit to address the privacy claims arising from this incident. The Credit Pros is a fintech company specializing in credit repair and monitoring services. The breach's full scope and the number of affected individuals are still being assessed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track The Credit Pros in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…