HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Inca Floats
bd_db3136e3051410ea · schema v1 · pii pii-v1
Full breach record for Inca Floats →Inca Floats, Inc. (dba International Nature & Cultural Adventures) notified the Maryland AG of a November 2024 incident where an unauthorized third party attempted to infiltrate its network. 14 Maryland residents were potentially affected; names, DOB, and passport numbers may have been exposed. No exfiltration confirmed. Credit monitoring offered.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5c074a411cc4b47aNew Hampshire State AGfiled 2025-03-21(398d gap)Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376220%20%281%29.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- 3f183b7b1d1b014633e517ab6dec8e1bd8c8994c0216ad8cb226697ee7e8f2fc
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- Inca Floatsnorm: inca floats
Incident
- Discovered
- Nov 24, 2024
- Materiality determined
- —
- Notification sent
- Jan 17, 2025
- Affected individuals
- 14
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- submitted its original notification letter to the Maryland Attorney General on January 21, 2025
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 months(515 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.