INFOSYS MCCAMISH SYSTEMS, LLC
bd_4ade75ab9c30c37c · schema v1 · pii pii-v1
Full breach record for INFOSYS MCCAMISH SYSTEMS, LLC →Infosys McCamish Systems LLC (IMS) experienced a cybersecurity event on or around November 3, 2023, where an unauthorized third party accessed IMS systems. IMS provides services for deferred compensation plans, including those serviced by Bank of America. IMS notified Bank of America on November 24, 2023, that data concerning these plans may have been compromised. IMS retained a third-party forensic firm to investigate and assist with recovery, including containing malicious activity and rebuilding systems. IMS states it has found no evidence of continued threat actor access. The incident likely involved personal information of plan participants, including names, addresses, business emails, dates of birth, Social Security numbers, and account information. Bank of America is providing a complimentary two-year identity theft protection membership through Experian IdentityWorks to affected individuals.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_57f59a9efd155380Delaware State AGfiled 2024-02-01Candidate
- bd_23c5e8946f81312aWashington State AGfiled 2024-02-02(1d gap)Verified
- bd_70d0e38dcbff117cOregon State AGfiled 2024-02-02(1d gap)Verified
- bd_c84589f45ed51923California State AGfiled 2024-02-02(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 29d gap
- bd_9a0b1407b634ebf0Oregon State AGfiled 2024-03-01(29d gap)Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/02/Sample-Letter-to-Participants.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 1, 2024
- Raw hash
- 821b9231d449029b199e499140966440f432def5abcf87a8eb8b9a25b0070e3a
Reporting entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Victim entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Incident
- Discovered
- Nov 3, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.