MalwareCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumResolved
Incorporating Services, Ltd.
bd_2c86ec42d18dfea2 · schema v1 · pii pii-v1
Full breach record for Incorporating Services, Ltd. →Incorporating Services, Ltd. disclosed that on April 2, 2012, its internet hosting vendor informed the company that a server was compromised by a malware attack. The malicious software allowed an unauthorized party to access data, including Social Security numbers of corporate officers and financial data (credit card numbers, security codes, bank account/routing numbers) for clients. The company investigated, replaced the server, engaged a new vendor, and offered one year of identity protection services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-23127
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 2, 2012
- Raw hash
- fbc8c12f2ae4cfb06d19631c25886891cf75e082f18c6cc5ad4e3098e7313a23
Reporting entity
- Name
- Incorporating Services, Ltd.norm: incorporating services
Victim entity
- Name
- Incorporating Services, Ltd.norm: incorporating services
Incident
- Discovered
- Apr 2, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via internet hosting vendor
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.