HackingHealthcareProfessional ServicesHealthcareStolen CredentialsCapture App DataCustomer Data InvolvedData ExfiltratedPCIPIILowResolved
The Institute for Functional Medicine
bd_352f7809cffc4ce1 · schema v1 · pii pii-v1
Full breach record for The Institute for Functional Medicine →IFM experienced a web skimmer attack (May 22-29, 2024): attacker stole an employee password, installed malicious software on IFM's website, and potentially intercepted purchase data including cardholder name, address, phone, card number, expiration date, and CVV. Malware removed May 29; credentials reset. 289 total affected; 1 Maine resident.
Maine clockDiscovered May 29, 2024 → Filed with AG Jul 22, 202454d ⏱ ME AG >30d8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1f5b663dae47e0d8Vermont State AGfiled 2024-07-23(1d gap)Verified
- bd_0d3e6c3fca5b01fdIndiana State AGfiled 2024-06-28(24d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/4600d1c1-badb-4092-bf6b-5d5c574cdeec.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2024
- Raw hash
- cc3834e3c1395f928ffe238cc2bc41c57699e036647179323881a9997830459d
Reporting entity
- Name
- The Institute for Functional Medicinenorm: the institute for functional medicine
- Domain
- ifm.org
- Industry
- Non-Profit
Victim entity
- Name
- The Institute for Functional Medicinenorm: the institute for functional medicine
- Domain
- ifm.org
- Industry
- Non-Profit
- Industry
- HealthcarellmProfessional Servicesllm
Incident
- Discovered
- May 29, 2024
- Materiality determined
- —
- Notification sent
- Jun 28, 2024
- Affected individuals
- 1
- Data types
- PCIPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1505.003 Server Software Component: Web ShellT1056.003 Input Capture: Web Portal Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement of the attack
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- ME AG >30d · 54d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 29, 2024→ Filed with AG: Jul 22, 202454d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.