HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICMediumContained
IMA
bd_878291acd9c7efad · schema v1 · pii pii-v1
Full breach record for IMA →IMA Diligence Services, LLC notified Rhode Island residents that an unauthorized actor accessed a decommissioned third-party file server between Dec 8-16, 2025. The incident involved the exfiltration of names and identity data affecting approximately 1,464 individuals. IMA engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring via Cyberscout.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_16e5e71a5f499131Maine State AGfiled 2026-05-29Verified
- bd_251ec6b205f440aeOregon State AGfiled 2026-05-29Verified by operator
- bd_3bd537247ac6bc06New Hampshire State AGfiled 2026-05-29Verified
- bd_4c7e828b89582965Vermont State AGfiled 2026-05-29Verified
Show 5 more filings ↓Show fewer ↑up to 28d gap
- bd_5cecf8343e66696fIndiana State AGfiled 2026-05-29Verified
- bd_c997f1d0e86131f5California State AGfiled 2026-05-29Verified
- bd_ccd420ce52718acdWashington State AGfiled 2026-05-29Verified by operator
- bd_8f50a59fb1559a98South Carolina State AGfiled 2026-06-01(3d gap)Verified
- bd_ec7a7a80f0d522baMassachusetts State AGfiled 2026-05-01(28d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/06/IMA-Diligence-Services-LLC-Notice-of-Data-Event.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2026
- Raw hash
- a201857b7424fa1e237c5c65bc04cc60fb67e121c0cb4103db586433776c902d
Reporting entity
- Name
- IMAnorm: ima
- Domain
- imanet.org
Victim entity
- Name
- IMAnorm: ima
- Domain
- imanet.org
Incident
- Discovered
- Dec 16, 2025
- Materiality determined
- —
- Notification sent
- May 29, 2026
- Affected individuals
- 1,464
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified applicable regulatory authorities where necessary
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 weeks(164 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.