HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
INFOSYS MCCAMISH SYSTEMS, LLC
bd_c84589f45ed51923 · schema v1 · pii pii-v1
Full breach record for INFOSYS MCCAMISH SYSTEMS, LLC →Infosys McCamish Systems LLC (IMS) experienced a cybersecurity event on or around November 3, 2023, when an unauthorized third party accessed IMS systems. The incident potentially compromised deferred compensation plan information for participants in plans serviced by Bank of America, including names, addresses, dates of birth, Social Security numbers, and account information. IMS retained a forensic firm, contained the threat, and rebuilt systems. Bank of America is offering two years of complimentary identity theft protection via Experian.
California clockDiscovered Nov 3, 2023 → Notified Nov 24, 202321d ✓ CA 60-day OK13 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_23c5e8946f81312aWashington State AGfiled 2024-02-02Verified
- bd_70d0e38dcbff117cOregon State AGfiled 2024-02-02Verified
- bd_4ade75ab9c30c37cDelaware State AGfiled 2024-02-01(1d gap)Candidate
- bd_57f59a9efd155380Delaware State AGfiled 2024-02-01(1d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 28d gap
- bd_9a0b1407b634ebf0Oregon State AGfiled 2024-03-01(28d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-580463
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 2, 2024
- Raw hash
- f48b8fc4c5f30ef41e1cb86516edf9c859d89a6422672804985c56154564082b
Reporting entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Victim entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Incident
- Discovered
- Nov 3, 2023
- Materiality determined
- —
- Notification sent
- Nov 24, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 3, 2023→ Notified: Nov 24, 202321d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.