HackingStolen CredentialsVulnerability ExploitData ExfiltratedTargetedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
The Institute for Functional Medicine
bd_1f5b663dae47e0d8 · schema v1 · pii pii-v1
Full breach record for The Institute for Functional Medicine →The Institute for Functional Medicine experienced a data breach between May 22-29, 2024, where an attacker used stolen employee credentials to install malicious software on its website. The malware potentially intercepted purchase information, including credit card details and personal data, from customers who made purchases during that window. IFM removed the malware, reset credentials, and notified law enforcement.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_352f7809cffc4ce1Maine State AGfiled 2024-07-22(1d gap)Candidate
- bd_0d3e6c3fca5b01fdIndiana State AGfiled 2024-06-28(25d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-07-23-institute-functional-medicine-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 23, 2024
- Raw hash
- 3d8b0956fdad6137461701f23380a1e59c1d5fad3bd384dac6fd797f52fe8610
Reporting entity
- Name
- The Institute for Functional Medicinenorm: the institute for functional medicine
- Domain
- ifm.org
Victim entity
- Name
- The Institute for Functional Medicinenorm: the institute for functional medicine
- Domain
- ifm.org
Incident
- Discovered
- May 29, 2024
- Materiality determined
- —
- Notification sent
- May 31, 2024
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.