HackingStolen CredentialsCustomer Data InvolvedDownstream VictimsPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Imagine360
bd_0f8c577caa8ceb5e · schema v1 · pii pii-v1
Full breach record for Imagine360 →Imagine360, LLC notified New Hampshire residents that unauthorized access to an employee's email account occurred on May 10 and May 16, 2024. The company discovered the breach on January 24, 2025. Personal information and protected health information were accessible in the emails. No evidence of data download or copying was found. Imagine360 reset passwords, enhanced email security, and offered credit monitoring to affected individuals.
Leak gap clock✗ Leak >180d6 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed27 affectedView incident
A leak claim by cl0p about this victim predates this filing by 714 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/imagine360-20250307.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 7, 2025
- Raw hash
- da75bdecb23d60eff372209b8aa6003f240c634109e2b653f2e06ec8076fe4af
Reporting entity
- Name
- Imagine360 Jobsnorm: imagine360 jobs
- Domain
- imagine360.isolvedhire.com
Victim entity
- Name
- Imagine360norm: imagine360
- Domain
- imagine360.com
Incident
- Discovered
- Jan 24, 2025
- Materiality determined
- —
- Notification sent
- Mar 7, 2025
- Affected individuals
- 27
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Providing written notice of this event to relevant state regulatorsProviding notice on Imagine360’s website pursuant to the Health Insurance Portability and Accountability Act (HIPAA)The U.S. Department of Health and Human Services will be receiving supplemental notice of this event
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.