HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
IMA
bd_c997f1d0e86131f5 · schema v1 · pii pii-v1
Full breach record for IMA →IMA Diligence Services, LLC notified the California Attorney General of a data breach affecting personal information. An unauthorized actor accessed files on a legacy server managed by a third-party between December 8 and December 16, 2025. The company discovered the incident on December 16, 2025. Affected data includes names and potentially other personal information. The company engaged cybersecurity specialists, notified law enforcement, and is offering 12 months of credit monitoring to affected individuals. The incident is contained.
California clockDiscovered Dec 16, 2025 → Notified May 29, 2026164d ✗ CA 60-day late23 weeks discovery → filing
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_16e5e71a5f499131Maine State AGfiled 2026-05-29Verified
- bd_251ec6b205f440aeOregon State AGfiled 2026-05-29Verified by operator
- bd_3bd537247ac6bc06New Hampshire State AGfiled 2026-05-29Verified
- bd_4c7e828b89582965Vermont State AGfiled 2026-05-29Verified
Show 5 more filings ↓Show fewer ↑up to 28d gap
- bd_5cecf8343e66696fIndiana State AGfiled 2026-05-29Verified
- bd_878291acd9c7efadDelaware State AGfiled 2026-05-29Verified
- bd_ccd420ce52718acdWashington State AGfiled 2026-05-29Verified by operator
- bd_8f50a59fb1559a98South Carolina State AGfiled 2026-06-01(3d gap)Verified
- bd_ec7a7a80f0d522baMassachusetts State AGfiled 2026-05-01(28d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624137
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2026
- Raw hash
- 715dd86a818a7a4749ca4db955676ee224680076ebd1f02c568426453c21c1cd
Reporting entity
- Name
- IMAnorm: ima
- Domain
- imanet.org
Victim entity
- Name
- IMAnorm: ima
- Domain
- imanet.org
Incident
- Discovered
- Dec 16, 2025
- Materiality determined
- —
- Notification sent
- May 29, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcementWill notify applicable regulatory authorities where necessary
- Third party
- via Third-party server manager
Compliance
- Time to disclose
- 23 weeks(164 days from discovery to filing)
- Compliance flags
- CA 60-day late · 164dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 16, 2025→ Notified: May 29, 2026164d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: May 29, 2026→ AG copy submitted: May 29, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.