HackingVulnerability ExploitStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Interstate Management Company, LLC
bd_c3abfae1f8e44f33 · schema v1 · pii pii-v1
Full breach record for Interstate Management Company, LLC →Interstate Management Company, LLC reported an external system breach (hacking) occurring on November 19, 2025, discovered on April 23, 2026. The incident affected 22,743 individuals, including 3 Maine residents. Data types compromised included names, personal identifiers, and government IDs. The company notified affected individuals in writing on May 26, 2026, and provided 12 months of credit monitoring via IDX.
Maine clockDiscovered Apr 23, 2026 → Filed with AG May 26, 202633d ⏱ ME AG >30d5 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_604a38f9d0f90394California State AGfiled 2026-05-26Verified
- bd_6b1874efb28835fcTexas State AGfiled 2026-05-28(2d gap)Verified by operator
- bd_76511e81864b7702Massachusetts State AGfiled 2026-05-01(25d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/fcbafb44-97d6-4512-8177-8d2528648275.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2026
- Raw hash
- d8ebe5241f66673dda631285de40959d99e2bcb163e01d893dd47ec435f0b1e4
Reporting entity
- Name
- Interstate Management Company, LLCnorm: interstate management
Victim entity
- Name
- Interstate Management Company, LLCnorm: interstate management
Incident
- Discovered
- Apr 23, 2026
- Materiality determined
- —
- Notification sent
- May 26, 2026
- Affected individuals
- 22,743
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notification with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- ME AG >30d · 33d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 23, 2026→ Filed with AG: May 26, 202633d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.