HackingStolen CredentialsCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Imagine360
bd_1718d44f4d0cba7f · schema v1 · pii pii-v1
Full breach record for Imagine360 →Imagine360, LLC notified consumers of a data breach involving third-party file-sharing platforms (Citrix and Fortra). Unauthorized actors copied files containing personal information (names, government IDs) between Jan 28-30, 2023. Imagine360 terminated access, reset passwords, engaged in investigations, reported to law enforcement, and offered 1-2 years of identity monitoring. The incident is classified as a third-party supply chain compromise.
Vermont clock✗ VT AG >45 bday22 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 98 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_d0676e61d4aa00a7Leak Sitecl0pfiled 2023-03-24(98d gap)Candidate
Regulatory filings (4) · sorted by filing gap
- bd_b386c892046d8ce5California State AGfiled 2023-06-30Verified by operator
- bd_0f408a234cac6f23New Hampshire State AGfiled 2023-07-05(5d gap)Verified
- bd_672151c19bdbe3e7New Hampshire State AGfiled 2023-07-21(21d gap)Verified
- bd_c10a588a7b8222e6California State AGfiled 2023-07-21(21d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-30-imagine360-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2023
- Raw hash
- 3c4303823fbda986e237c1ffd8193ec7eb041d07ff53afebbfc10056cd60c640
Reporting entity
- Name
- Imagine360norm: imagine360
- Domain
- imagine360.com
Victim entity
- Name
- Imagine360norm: imagine360
- Domain
- imagine360.com
Incident
- Discovered
- Jan 30, 2023
- Materiality determined
- Jun 1, 2023
- Notification sent
- Jun 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported these incidents to federal law enforcementNotifying applicable state and federal regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 weeks(151 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.