HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
INDEPENDENT LIVING SYSTEMS, LLC.
bd_079ab087cc11a88d · schema v1 · pii pii-v1
Full breach record for INDEPENDENT LIVING SYSTEMS, LLC. →Independent Living Systems, LLC (ILS) disclosed a data event affecting approximately 791 Delaware residents. Unauthorized access to ILS systems occurred between June 30 and July 5, 2022. The incident involved the acquisition of personal information, including names, Social Security numbers, and medical/health insurance information. IIS engaged outside cybersecurity specialists, notified federal law enforcement, and provided credit monitoring services via Experian to affected individuals. Written notice to Delaware residents began on March 14, 2023.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_49658d88790892d4Delaware State AGfiled 2023-03-14Candidate
- bd_76c01be0d4d4db85Montana State AGfiled 2023-03-14Verified
- bd_84567d80dc06c6aeWashington State AGfiled 2023-03-14Verified
- bd_d12a4e9779e6cd28Vermont State AGfiled 2023-03-14Verified
Show 3 more filings ↓Show fewer ↑up to 6d gap
- bd_e02e5929cfeffa36California State AGfiled 2023-03-14Verified
- bd_e2b81beb1d2897a6Oregon State AGfiled 2023-03-14Verified
- bd_eba48fd5c2b29c1dNew Hampshire State AGfiled 2023-03-20(6d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/03/ILS-Notice-of-Data-Event-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2023
- Raw hash
- 71102a744dffe690b9dba50233515dba5559935384eb04c6c5990e26f655be5c
Reporting entity
- Name
- INDEPENDENT LIVING SYSTEMS, LLC.norm: independent living
Victim entity
- Name
- INDEPENDENT LIVING SYSTEMS, LLC.norm: independent living
Incident
- Discovered
- Jul 5, 2022
- Materiality determined
- —
- Notification sent
- Mar 14, 2023
- Affected individuals
- 791
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified state and federal regulators, as requiredproviding notice to the three major consumer reporting agencies (i.e., Equifax, Experian, and TransUnion)notifying the U.S. Department of Health and Human Services and prominent media pursuant to HIPAA
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 36 weeks(252 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.