HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
IMA
bd_3bd537247ac6bc06 · schema v1 · pii pii-v1
Full breach record for IMA →IMA Diligence Services, LLC reported a data event affecting 200 New Hampshire residents. Unauthorized access occurred on a legacy third-party server between December 8 and December 16, 2025. Exposed data included names, driver's license numbers, Social Security numbers, and financial account information. IMA Diligence engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring via TransUnion/Cyberscout. Notice was filed with the NH Attorney General on May 29, 2026.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_16e5e71a5f499131Maine State AGfiled 2026-05-29Verified
- bd_251ec6b205f440aeOregon State AGfiled 2026-05-29Verified by operator
- bd_4c7e828b89582965Vermont State AGfiled 2026-05-29Verified
- bd_5cecf8343e66696fIndiana State AGfiled 2026-05-29Verified
Show 5 more filings ↓Show fewer ↑up to 28d gap
- bd_878291acd9c7efadDelaware State AGfiled 2026-05-29Verified
- bd_c997f1d0e86131f5California State AGfiled 2026-05-29Verified
- bd_ccd420ce52718acdWashington State AGfiled 2026-05-29Verified by operator
- bd_8f50a59fb1559a98South Carolina State AGfiled 2026-06-01(3d gap)Verified
- bd_ec7a7a80f0d522baMassachusetts State AGfiled 2026-05-01(28d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ima-diligence-services-20260529.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2026
- Raw hash
- ea9e07a2a8d80f1ecd8df466aac70d2d3c2167ef19dbe9c7cce764f72928805f
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- IMAnorm: ima
- Domain
- imanet.org
Incident
- Discovered
- Dec 16, 2025
- Materiality determined
- —
- Notification sent
- May 29, 2026
- Affected individuals
- 200
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement regarding the eventProvided written notice of this incident to relevant state regulators, as necessary, and to the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 weeks(164 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.