Ivenix
bd_3a4aab3667b54844 · schema v1 · pii pii-v1
Full breach record for Ivenix →Fresenius Kabi USA, LLC notified the New Hampshire Attorney General of a data incident involving its subsidiary, Ivenix. Between January 6 and January 9, 2026, an unauthorized third party accessed Ivenix's network using valid credentials. The incident affected approximately 131 New Hampshire residents, exposing names, contact info, SSNs, driver's license numbers, and financial account numbers. Fresenius discovered the breach on January 8, 2026, contained the threat, and began notifying affected individuals on June 17, 2026, offering 24 months of credit monitoring. No evidence of data exfiltration was found, but the data types suggest potential identity theft risk.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/fresenius-kabi-usa-20260622.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 22, 2026
- Raw hash
- 423a036b3d6deca01ec8c1d5dde7771152c07f92757b0abae77a48b8556fa549
Reporting entity
- Name
- Fresenius Kabi USA, LLCnorm: fresenius kabi usa
Victim entity
- Name
- Ivenixnorm: ivenix
Incident
- Discovered
- Jan 8, 2026
- Materiality determined
- —
- Notification sent
- Jun 17, 2026
- Affected individuals
- 131
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 weeks(165 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.