HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Optalis
bd_d0ddbee6dbc4ef51 · schema v1 · pii pii-v1
Full breach record for Optalis →Optalis Management Solutions experienced unauthorized network access between April 14 and 19, 2025. The incident compromised personal information including names, Social Security numbers, driver's license numbers, credit/debit card details, financial account information, and medical/health insurance data. The company engaged outside cybersecurity professionals for investigation and offered IDX identity protection services, including credit monitoring and ID theft recovery, to affected individuals. Notification was sent on June 25, 2026.
Massachusetts clock✗ MA AG >90d14 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1061-optalis-management-solutions/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- a79ea0d761fcdd7f8ae47bcffc4d17fa9ba316d3ace68b51df4a68f4f4cfb10d
Reporting entity
- Name
- Optalisnorm: optalis
- Domain
- optalis.org
Victim entity
- Name
- Optalisnorm: optalis
- Domain
- optalis.org
Incident
- Discovered
- Apr 14, 2025
- Materiality determined
- —
- Notification sent
- Jun 25, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(413 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.