DisclosureLens
MalwareFinancial ServicesFinanceRansomwareSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDMediumContained

Newport

bd_9247d9734b1c370e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 2, 2023

Filed

Feb 16, 2024

To disclose

15 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for Newport →

Newport Group, Inc. notified participants of a ransomware event affecting its third-party vendor, Infosys McCamish Systems (IMS), on November 2, 2023. The breach date is listed as October 29, 2023. IMS processes transactions for non-qualified deferred compensation plans. While IMS stated there is no evidence that participant information (name, address, date of birth, SSN) was impacted, Newport offered one year of complimentary identity protection through Experian as a precaution. Unit 42 and EY were engaged for security validation and e-discovery. The IMS environment was restored and hardened.

Incident timeline

undetected · 4 days
discovery → filing · 15 weeks / 106 days

Oct 29, 2023

Begins

Nov 2, 2023

Discovered

Feb 16, 2024

Filed

vs. sector median

+5 wks slower

Part of INFOSYS MCCAMISH SYSTEMS, LLC supply-chain incident (2024) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.