HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
International Center of Photography
bd_75abf37bcfdf2f05 · schema v1 · pii pii-v1
Full breach record for International Center of Photography →The International Center of Photography (ICP) disclosed a cybersecurity incident on February 16, 2023, where an unauthorized individual accessed its network. Files containing customer information, including names, government IDs, passport numbers, bank account numbers, and Social Security numbers, may have been viewed or taken. ICP engaged cybersecurity specialists and conducted reviews to identify affected individuals. The notice covers residents of multiple states, including Delaware, New York, and Massachusetts.
Leak gap clock✗ Leak >180d51 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 353 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_e2ef7dae4dfb60ebMaine State AGfiled 2024-02-07Candidate
- bd_8a9e8ea0e8a06b6fMontana State AGfiled 2024-02-08(1d gap)Verified
- bd_0e29c34fc9df6ae0New Hampshire State AGMedusafiled 2024-02-15(8d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/02/2024JAN22-DRAFT-Notice-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 7, 2024
- Raw hash
- 43c4fefb1c4dafeb26f4e3c8139dd059fde158ef929f4a556bee2804170af55f
Reporting entity
- Name
- International Center of Photographynorm: international center of photography
- Domain
- icp.org
Victim entity
- Name
- International Center of Photographynorm: international center of photography
- Domain
- icp.org
Incident
- Discovered
- Feb 16, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 51 weeks(356 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.