HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
ERMI
bd_6f3c9fcbecab88f2 · schema v1 · pii pii-v1
Full breach record for ERMI →ERMI LLC notified the California Attorney General of an incident where an unauthorized individual accessed employee email accounts. The breach occurred between February 15, 2025, and August 14, 2025, and was discovered on July 25, 2025. Personal information, including medical data, may have been accessed or removed. The company engaged external cybersecurity professionals and is offering credit monitoring services to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9f7664f300747a66Massachusetts State AGfiled 2026-05-01(25d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-623952
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2026
- Raw hash
- 1c43638d08365f7cf7fbaec99bc8f3bcd14f938c18de154352880780e09e19ac
Reporting entity
- Name
- ERMInorm: ermi
- Domain
- ermi-motion.com
Victim entity
- Name
- ERMInorm: ermi
- Domain
- ermi-motion.com
Incident
- Discovered
- Jul 25, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 44 weeks(305 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.