MalwareRansomwareMedusaData ExfiltratedRansom DemandedCustomer Data InvolvedDownstream VictimsPIIIDENTITY_BASICLowContained
International Center of Photography
bd_0e29c34fc9df6ae0 · schema v1 · pii pii-v1
Full breach record for International Center of Photography →International Center of Photography (ICP) reported a ransomware incident involving the Medusa threat actor, discovered on February 16, 2023. The attack resulted in data exfiltration and encryption. ICP engaged forensic experts, rebuilt its network infrastructure, and implemented enhanced security controls including MFA and network segmentation. Two data subjects in New Hampshire were impacted. ICP did not pay the ransom.
Leak gap clock✗ Leak >180d52 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 361 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_8a9e8ea0e8a06b6fMontana State AGfiled 2024-02-08(7d gap)Verified
- bd_75abf37bcfdf2f05Delaware State AGfiled 2024-02-07(8d gap)Verified
- bd_e2ef7dae4dfb60ebMaine State AGfiled 2024-02-07(8d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/international-center-photography-20240215.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2024
- Raw hash
- 0cbad79b906b18bad9f12b8006c061d33f0d2bb1642a851c19de64bcd8bb10ba
Reporting entity
- Name
- International Center of Photographynorm: international center of photography
- Domain
- icp.org
Victim entity
- Name
- International Center of Photographynorm: international center of photography
- Domain
- icp.org
Incident
- Discovered
- Feb 16, 2023
- Materiality determined
- Dec 15, 2023
- Notification sent
- —
- Affected individuals
- 2
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- MedusaExternalFinancial
Compliance
- Time to disclose
- 52 weeks(364 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.