Snow lingered outside the office building of Receivables Performance Management on Thursday, Dec. 1, 2022, in Lynnwood, Washington. (Olivia Vanni / The Herald)

Snow lingered outside the office building of Receivables Performance Management on Thursday, Dec. 1, 2022, in Lynnwood, Washington. (Olivia Vanni / The Herald)

Lynnwood data breach exposed sensitive info for 3.7 million across US

Lawsuits allege lax security at a debt collection agency led to the attack. It wasn’t announced for over a year.

LYNNWOOD — A security breach at a Lynnwood-based debt collection agency jeopardized sensitive personal information for more than 3 million people across the country last year.

And the company, Receivables Performance Management, failed to notify potential victims for over 18 months. It wasn’t until late last month the company sent notices alerting people their social security numbers and names may have been accessed.

The Lynnwood company now faces a slew of lawsuits in federal court in Seattle. The complaints allege the company violated state law due to an alleged lack of security and the delay in notifying people of the breach. The four plaintiffs are from Georgia, New Jersey, North Carolina and Pennsylvania. Several of them had fraudulent activity on their bank accounts before they were notified of the breach.

An attorney for the plaintiffs, Kaleigh Boyd of Seattle law firm Tousley Brain Stephens, declined to comment Wednesday.

Tom Loeser, a lawyer with Hagens Berman, also of Seattle, told The Daily Herald his firm has heard from several other people who received the notice. He has lots of questions as his firm investigates the ransomware attack.

“When did they learn about it?” Loeser said. “When did they get the ransom message? And why didn’t they tell people then? Were they working with the hackers to try to get the information back? Were they going to keep it close to their vests and not tell anybody until they thought they resolved it?”

Loeser, a former federal prosecutor in California who handled cyber crime cases, suggested those affected should freeze their accounts at all three of the credit bureaus. And if one pays for anything to protect their data, be sure to keep the receipts.

In the notice to those affected, the company advised people closely monitor “all mail, email, or other contact from individuals not known to you personally, and to avoid answering questions or providing additional information to such unknown individuals.”

The company and its lawyer didn’t immediately respond to a request for comment.

Many clients whose data was breached wouldn’t even know Receivables Performance Management had their personal information, Loeser said. It simply collects debt while working with companies in various sectors, including health care, banking and utilities.

The attack

On May 12, 2021, the company became aware of a “data security incident,” according to the notice sent Nov. 21, 2022.

Its investigation found the hackers first accessed the company’s server a month earlier, on April 8. The ransomware attack was launched in May, exposing personal information for 3,766,573 people.

The company immediately disconnected all of its electronic equipment and began restoring its systems, according to the notice.

In the notice, Receivables Performance Management’s CEO Howard George wrote that the company’s data review process lasted until early October of this year.

“Through this review process, RPM identified the presence of your personal information in the files that were reviewed, including Social Security number,” George wrote. “Please note that it is entirely possible that your specific personal information was not impacted as a result of the incident. RPM also obtained confirmation to the best of its ability that the information is no longer in the possession of the third party(ies) associated with this incident.”

The CEO wrote that the company “deeply regrets any concern this may have caused you.”

It’s unclear if the company paid a ransom to get the data back or where the sensitive information is now. And it’s unknown who got the data.

“I don’t know that there is a world of honest thieves out there,” Loeser said. “There is absolutely no guarantee that paying a ransom in a ransomware attack means that the hacker will all of the sudden be altruistic and choose not to sell all of the information they stole on the Dark Web. You have to remember that they stole the information to begin with.”

Receivables Performance Management offered a free yearlong subscription to a credit monitoring and identity theft protection service. The company encouraged clients to contact it at 877-237-5382 for more information.

Loeser said the yearlong protection is “grossly insufficient.” Sometimes, hackers will hold on to the information for years, wait until people have their guards down and then use it.

The lawsuits allege the Lynnwood company failed to “maintain an adequate data security system to reduce the risk of data breaches.” Loeser said the fact the hack happened at all shows its data security efforts weren’t enough.

The debt collection company’s privacy policy on its website states: “As financial services professionals entrusted with sensitive information, we respect the privacy of our clients, and the privacy of their customers. We are committed to treating customer’s information responsibly.”

It’s likely more lawsuits will be filed against Receivables Performance Management. Those would probably then be consolidated into one class-action case.

A spokesperson for the Federal Trade Commission declined to comment on whether the agency was investigating the attack. A spokesperson for the state Office of the Attorney General didn’t immediately respond to a request for comment.

This article has been updated that Loeser suggested freezing credit bureau accounts.

Jake Goldstein-Street: 425-339-3439; jake.goldstein-street@heraldnet.com; Twitter: @GoldsteinStreet.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Snohomish County Health Department Director Dennis Worsham on Tuesday, June 11, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Snohomish County Health Department director tapped as WA health secretary

Dennis Worsham became the first director of the county health department in January 2023. His last day will be July 3.

Marysville is planning a new indoor sports facility, 350 apartments and a sizable hotel east of Ebey Waterfront Park. (Olivia Vanni / The Herald)
New report shifts outlook of $25M Marysville sports complex

A report found a conceptual 100,000-square-foot sports complex may require public investment to pencil out.

Police Cmdr. Scott King answers questions about the Flock Safety license plate camera system on Thursday, June 5, 2025 in Mountlake Terrace, Washington. (Olivia Vanni / The Herald)
Mountlake Terrace approves Flock camera system after public pushback

The council approved the $54,000 license plate camera system agreement by a vote of 5-2.

Cascadia College Earth and Environmental Sciences Professor Midori Sakura looks in the surrounding trees for wildlife at the North Creek Wetlands on Wednesday, June 4, 2025 in Bothell, Washington. (Olivia Vanni / The Herald)
Cascadia College ecology students teach about the importance of wetlands

To wrap up the term, students took family and friends on a guided tour of the North Creek wetlands.

Community members gather for the dedication of the Oso Landslide Memorial following the ten-year remembrance of the slide on Friday, March 22, 2024, at the Oso Landslide Memorial in Oso, Washington. (Ryan Berry / The Herald)
The Daily Herald garners 6 awards from regional journalism competition

The awards recognize the best in journalism from media outlets across Alaska, Idaho, Montana, Oregon and Washington.

Edmonds Mayor Mike Rosen goes through an informational slideshow about the current budget situation in Edmonds during a roundtable event at the Edmonds Waterfront Center on Monday, April 7, 2025 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds mayor recommends $19M levy lid lift for November

The city’s biennial budget assumed a $6 million levy lid lift. The final levy amount is up to the City Council.

A firefighting helicopter carries a bucket of water from a nearby river to the Bolt Creek Fire on Saturday, Sep. 10, 2022, on U.S. 2 near Index, Washington. (Ryan Berry / The Herald)
How Snohomish County property owners can prepare for wildfire season

Clean your roofs, gutters and flammable material while completing a 5-foot-buffer around your house.

(City of Everett)
Everett’s possible new stadium has a possible price tag

City staff said a stadium could be built for $82 million, lower than previous estimates. Bonds and private investment would pay for most of it.

Jennifer Humelo, right, hugs Art Cass outside of Full Life Care Snohomish County on Wednesday, May 28, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
‘I’ll lose everything’: Snohomish County’s only adult day health center to close

Full Life Care in Everett, which supports adults with disabilities, will shut its doors July 19 due to state funding challenges.

Logo for news use featuring Snohomish County, Washington. 220118
Snohomish County Board of Health looking to fill vacancy

The county is accepting applications until the board seat is filled.

A recently finished log jam is visible along the Pilchuck River as a helicopter hovers in the distance to pick up a tree for another log jam up river on Wednesday, June 11, 2025 in Granite Falls, Washington. (Olivia Vanni / The Herald)
Tulalip Tribes and DNR team up on salmon restoration project along the Pilchuck River

Tulalip Tribes and the state Department of Natural Resources are creating 30 log jams on the Upper Pilchuck River for salmon habitat.

Everett High School graduate Gwen Bundy high fives students at her former grade school Whittier Elementary during their grad walk on Thursday, June 12, 2018 in Everett, Wa. (Olivia Vanni / The Herald)
‘Literally the best’: Grads celebrated at Everett elementary school

Children at Whittier Elementary cheered on local high school graduates as part of an annual tradition.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.