HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Doxim
bd_520aa0b12540d115 · schema v1 · pii pii-v1
Full breach record for Doxim →Doxim, Inc. detected suspicious activity on December 30, 2023, within its credit union services network. Investigation revealed unauthorized access occurred between December 25 and December 30, 2023, resulting in the exfiltration of files containing names, addresses, account numbers, and Social Security numbers. Systems were taken offline, law enforcement notified, and cybersecurity experts engaged. Identity monitoring services are being offered to affected individuals.
Leak gap clock⏱ Leak >30d24 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_da56de92f3ee4e5fMontana State AGfiled 2024-06-13(1d gap)Candidate
- bd_46c60d7c1e44a8a7Delaware State AGfiled 2024-05-31(14d gap)Verified
- bd_c5e5240b71ffa580Indiana State AGfiled 2024-05-31(14d gap)Verified
- bd_e19d085c281090a7Vermont State AGfiled 2024-05-31(14d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 185d gap
- bd_db56f3d0be46da1aWashington State AGfiled 2024-12-11(180d gap)Verified
- bd_d6d4f9787b2aa530Oregon State AGfiled 2024-12-16(185d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586958
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 14, 2024
- Raw hash
- 6f827927fb0a4a0c32b10e9fb28e307f4fd915b8c0c516409ca720884d958618
Reporting entity
- Name
- Doximnorm: doxim
- Domain
- doxim.com
Victim entity
- Name
- Doximnorm: doxim
- Domain
- doxim.com
Incident
- Discovered
- Dec 30, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcementSupporting federal law enforcement’s criminal investigation
Compliance
- Time to disclose
- 24 weeks(167 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.