HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICLowContained
IMA
bd_8f50a59fb1559a98 · schema v1 · pii pii-v1
Full breach record for IMA →IMA Diligence Services, LLC notified South Carolina and other state regulators of a breach involving a decommissioned third-party legacy server. Unauthorized access occurred between Dec 8-16, 2025, exposing names and limited PII. No misuse confirmed. 12 months credit monitoring offered. ~1,464 Rhode Island residents impacted; total count undisclosed.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_16e5e71a5f499131Maine State AGfiled 2026-05-29(3d gap)Verified
- bd_251ec6b205f440aeOregon State AGfiled 2026-05-29(3d gap)Verified by operator
- bd_3bd537247ac6bc06New Hampshire State AGfiled 2026-05-29(3d gap)Verified
- bd_4c7e828b89582965Vermont State AGfiled 2026-05-29(3d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 31d gap
- bd_5cecf8343e66696fIndiana State AGfiled 2026-05-29(3d gap)Verified
- bd_878291acd9c7efadDelaware State AGfiled 2026-05-29(3d gap)Verified
- bd_c997f1d0e86131f5California State AGfiled 2026-05-29(3d gap)Verified
- bd_ccd420ce52718acdWashington State AGfiled 2026-05-29(3d gap)Verified by operator
- bd_ec7a7a80f0d522baMassachusetts State AGfiled 2026-05-01(31d gap)Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20IMA%20Diligence%20Services%2C%20LLC.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 696343e4bac0b68b61e5a690edbafe8b1ef7fa4cc668734327ac1fdb246f70c2
Reporting entity
- Name
- IMAnorm: ima
- Domain
- imanet.org
Victim entity
- Name
- IMAnorm: ima
- Domain
- imanet.org
Incident
- Discovered
- Dec 16, 2025
- Materiality determined
- —
- Notification sent
- May 29, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Will notify applicable regulatory authorities where necessary
Compliance
- Time to disclose
- 24 weeks(167 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.