HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
INFOSYS MCCAMISH SYSTEMS, LLC
bd_57f59a9efd155380 · schema v1 · pii pii-v1
Full breach record for INFOSYS MCCAMISH SYSTEMS, LLC →Infosys McCamish Systems LLC (IMS) experienced a cybersecurity event on or around November 3, 2023, where an unauthorized third party accessed IMS systems. IMS provides services for deferred compensation plans, including those serviced by Bank of America. The incident resulted in the potential compromise of participant data, including names, addresses, SSNs, and account information. IMS retained forensic investigators, contained the threat, and Bank of America is offering two years of complimentary identity theft protection to affected participants.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_4ade75ab9c30c37cDelaware State AGfiled 2024-02-01Candidate
- bd_23c5e8946f81312aWashington State AGfiled 2024-02-02(1d gap)Verified
- bd_70d0e38dcbff117cOregon State AGfiled 2024-02-02(1d gap)Verified
- bd_c84589f45ed51923California State AGfiled 2024-02-02(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 29d gap
- bd_9a0b1407b634ebf0Oregon State AGfiled 2024-03-01(29d gap)Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/02/Sample-Letter-to-Participants.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 1, 2024
- Raw hash
- 8c013d5ed1b4c6e0bed0af49d0b0c109d62124d3c47a109b401bceb49ecea7f9
Reporting entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Victim entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Incident
- Discovered
- Nov 3, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.