MalwareRansomwareData ExfiltratedData EncryptedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Innovative Service Technology Management Services, Inc.
bd_4bdf230a609e5c49 · schema v1 · pii pii-v1
Full breach record for Innovative Service Technology Management Services, Inc. →Innovative Service Technology Management Services, Inc. (IST) disclosed a ransomware attack on June 3, 2022, which impacted computer systems. An unauthorized actor gained access, potentially acquiring files before encrypting data. IST discovered on October 17, 2022, that personal information (name and government ID numbers) may have been compromised. IST took systems offline, reported to law enforcement, reset passwords, and enhanced endpoint detection. No actual misuse is known.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_443eb8e22d84e891California State AGfiled 2022-11-16Candidate
- bd_5c669fbfc9bd4325Maine State AGfiled 2022-11-16Verified
- bd_7af024916731e033Montana State AGfiled 2022-11-16Candidate
- bd_1581134e72c8011fHHS OCRfiled 2022-11-17(1d gap)Candidate
Source provenance
- Source URL
- https://ag.idaho.gov/content/uploads/2022/11/11-16-22-Innovative-Service-Technology-Management-Services-Inc..pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 16, 2022
- Raw hash
- 9491aeb3c8bbbf7ab69c0f550618b9e6572693cb27816bd2b6a703424a4e7d39
Reporting entity
- Name
- Innovative Service Technology Management Services, Inc.norm: innovative service technology management
Victim entity
- Name
- Innovative Service Technology Management Services, Inc.norm: innovative service technology management
Incident
- Discovered
- Jun 3, 2022
- Materiality determined
- —
- Notification sent
- Nov 16, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 weeks(166 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.