MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Unitransfer USA Inc.
bd_acf339197094da0c · schema v1 · pii pii-v1
Full breach record for Unitransfer USA Inc. →Omnex Group, Inc. reported a cybersecurity incident involving its third-party correspondent payer, Unitransfer USA Inc. On December 13, 2023, Unitransfer experienced a security breach involving malware and a ransomware attempt. The incident compromised data for 19 customers, including names, addresses, driver's license numbers, and bank information. Unitransfer engaged cybersecurity consultants to eliminate the malware and notified law enforcement. Omnex disabled the relationship with Unitransfer pending security assurances and is notifying affected customers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed19 affectedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2023/12/12-15-2023-Omnex-Group-Inc.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2023
- Raw hash
- fbd24dc222c89277fb432e94c9680b8b51c936efa41074a9c3d6183edce34740
Reporting entity
- Name
- Omnex Group, Inc.norm: omnex group
- Domain
- omnexgroup.com
Victim entity
- Name
- Unitransfer USA Inc.norm: unitransfer usa
Incident
- Discovered
- Dec 13, 2023
- Materiality determined
- —
- Notification sent
- Dec 15, 2023
- Affected individuals
- 19
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Served notice to Idaho State regulators (Consumer Protection Mailbox)
- Third party
- via Unitransfer USA Inc.correspondent payer / third-party service provider
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.