HackingIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Doxim
bd_46c60d7c1e44a8a7 · schema v1 · pii pii-v1
Full breach record for Doxim →Doxim Inc. reported a security incident on December 30, 2023, involving unauthorized access to its credit union services network. The breach exposed personal information, including names, addresses, account numbers, and Social Security numbers, of members of a data owner for whom Doxim prepares account statements and tax forms. Doxim took systems offline, notified law enforcement, and engaged cybersecurity experts. No evidence of misuse was found. Affected individuals were offered 12 months of credit monitoring via Kroll.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_c5e5240b71ffa580Indiana State AGfiled 2024-05-31Verified
- bd_e19d085c281090a7Vermont State AGfiled 2024-05-31Verified
- bd_da56de92f3ee4e5fMontana State AGfiled 2024-06-13(13d gap)Candidate
- bd_520aa0b12540d115California State AGfiled 2024-06-14(14d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 199d gap
- bd_db56f3d0be46da1aWashington State AGfiled 2024-12-11(194d gap)Verified
- bd_d6d4f9787b2aa530Oregon State AGfiled 2024-12-16(199d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/12/Example-Individual-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2024
- Raw hash
- ef2ef4922b4944905ede6ef4097cc5f9ac47a386f5ac4e90b6f56cdb2127d0fe
Reporting entity
- Name
- Doximnorm: doxim
- Domain
- doxim.com
Victim entity
- Name
- Doximnorm: doxim
- Domain
- doxim.com
Incident
- Discovered
- Dec 30, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- supporting federal law enforcement’s criminal investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 weeks(153 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.