HackingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICMediumContained
INFOSYS MCCAMISH SYSTEMS, LLC
bd_0886f1fbcbbe5578 · schema v1 · pii pii-v1
Full breach record for INFOSYS MCCAMISH SYSTEMS, LLC →Infosys McCamish Systems (IMS), a vendor for TIAA, experienced a cybersecurity incident on or around November 2, 2023, where an unauthorized party gained access to IMS systems. TIAA terminated connections and scanned its systems. IMS engaged forensic and e-discovery firms, implemented security controls, and restored services. TIAA began notifying 3,352 New Hampshire residents on March 7, 2024, offering credit monitoring.
This filing is one of 13 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_118ac386a65120dfWashington State AGfiled 2024-06-27(20d gap)Candidate
- bd_3c00e95f3727fd47Vermont State AGfiled 2024-06-27(20d gap)Verified
- bd_4cf04db073068a7fMontana State AGfiled 2024-06-27(20d gap)Verified
- bd_bf7aea3b027e4b99Delaware State AGfiled 2024-06-27(20d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 94d gap
- bd_113d2318c13a1bf9California State AGfiled 2024-06-28(21d gap)Verified
- bd_8df9b1b9b6a5a176California State AGfiled 2024-07-19(42d gap)Verified
- bd_4f0f0f3fd5c44be8Maine State AGfiled 2024-08-13(67d gap)Verified
- bd_09a55fdd2bbb246aCalifornia State AGfiled 2024-08-15(69d gap)Verified
- bd_2c639b79e4797456California State AGfiled 2024-09-09(94d gap)Verified
- bd_e4f30fd83097d2eaMaine State AGfiled 2024-09-09(94d gap)Verified
Showing first 10 of 12 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/infosys-mccamish-systems-20240607.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 7, 2024
- Raw hash
- a21c9ff033909c2b96be2632284c809e96404c1cc901fe0d5aacc0791b518447
Reporting entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Victim entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Incident
- Discovered
- Nov 2, 2023
- Materiality determined
- —
- Notification sent
- Mar 7, 2024
- Affected individuals
- 3,352
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 31 weeks(218 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.