HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICLowContained
Imagine360
bd_c10a588a7b8222e6 · schema v1 · pii pii-v1
Full breach record for Imagine360 →Imagine360, LLC notified the California AG of a data security incident involving unauthorized access to third-party file sharing platforms (Citrix and Fortra). An unauthorized actor copied data between January 28 and January 30, 2023. Imagine360 identified unusual activity on January 30, 2023, and was notified by Fortra on February 3, 2023. The incident involved personal information including names and potentially other health-related data. Imagine360 suspended use of the platforms, reset passwords, engaged in investigation, and offered identity monitoring services.
California clockDiscovered Jan 30, 2023 → Notified Jul 21, 2023172d ✗ CA 60-day late25 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_d0676e61d4aa00a7Leak Sitecl0pfiled 2023-03-24(119d gap)Candidate
Regulatory filings (4) · sorted by filing gap
- bd_672151c19bdbe3e7New Hampshire State AGfiled 2023-07-21Verified
- bd_0f408a234cac6f23New Hampshire State AGfiled 2023-07-05(16d gap)Verified
- bd_1718d44f4d0cba7fVermont State AGfiled 2023-06-30(21d gap)Verified
- bd_b386c892046d8ce5California State AGfiled 2023-06-30(21d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570680
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2023
- Raw hash
- a0c7e9efb6f1b42bbbd1bfbe1ef12e68485edf5b48529c2637abe289ffbdb5d0
Reporting entity
- Name
- Imagine360norm: imagine360
- Domain
- imagine360.com
Victim entity
- Name
- Imagine360norm: imagine360
- Domain
- imagine360.com
Incident
- Discovered
- Jan 30, 2023
- Materiality determined
- —
- Notification sent
- Jul 21, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported these incidents to federal law enforcementWill be notifying applicable state and federal regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 25 weeks(172 days from discovery to filing)
- Compliance flags
- CA 60-day late · 172dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 30, 2023→ Notified: Jul 21, 2023172d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.