HackingStolen CredentialsCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)IDENTITY_BASICPHIHEALTH_BASICLowContained
Imagine360
bd_b386c892046d8ce5 · schema v1 · pii pii-v1
Full breach record for Imagine360 →Imagine360, LLC notified the California AG of a data security incident involving third-party file sharing platforms (Citrix and Fortra). Unauthorized actors copied files between January 28 and January 30, 2023. Imagine360 identified unusual activity on January 30, 2023, and was notified by Fortra on February 3, 2023. The incident affected health insurance claim data, including names and potentially other PHI. Imagine360 terminated access, reset passwords, engaged law enforcement, and offered identity monitoring services.
California clockDiscovered Jan 30, 2023 → Notified Jun 30, 2023151d ✗ CA 60-day late22 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_d0676e61d4aa00a7Leak Sitecl0pfiled 2023-03-24(98d gap)Candidate
Regulatory filings (4) · sorted by filing gap
- bd_1718d44f4d0cba7fVermont State AGfiled 2023-06-30Verified
- bd_0f408a234cac6f23New Hampshire State AGfiled 2023-07-05(5d gap)Verified
- bd_672151c19bdbe3e7New Hampshire State AGfiled 2023-07-21(21d gap)Verified
- bd_c10a588a7b8222e6California State AGfiled 2023-07-21(21d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-568756
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2023
- Raw hash
- 1f5bfef41c9622db700900dde7caf2ebe0b209612d1d90e4ab4b6f13839dec0c
Reporting entity
- Name
- Imagine360norm: imagine360
- Domain
- imagine360.com
Victim entity
- Name
- Imagine360norm: imagine360
- Domain
- imagine360.com
Incident
- Discovered
- Jan 30, 2023
- Materiality determined
- —
- Notification sent
- Jun 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Will be notifying applicable state and federal regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 weeks(151 days from discovery to filing)
- Compliance flags
- CA 60-day late · 151dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 30, 2023→ Notified: Jun 30, 2023151d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.