HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
ITO EN (North America) INC.
bd_055624d682bed942 · schema v1 · pii pii-v1
Full breach record for ITO EN (North America) INC. →ITO EN (North America) INC. notified the Maryland Attorney General of a data security incident detected on December 2, 2024. An unauthorized third party attempted to enter the network and exfiltrate data. The incident affected 6 Maryland residents, exposing names, addresses, Social Security numbers, and financial account information. ITO EN engaged forensic investigators, secured its network, and offered 12 months of credit monitoring and identity theft protection services to affected individuals.
Maryland clock⏱ MD AG >30d9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed6 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376279.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 31, 2025
- Raw hash
- bfac73046e4f6b920d6d5e50f948dbf21e7c4d660149f3bab00d9f0938806bd6
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- ITO EN (North America) INC.norm: ito en north america
Incident
- Discovered
- Dec 2, 2024
- Materiality determined
- —
- Notification sent
- Jan 31, 2025
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.