HackingStolen CredentialsData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Doxim
bd_e19d085c281090a7 · schema v1 · pii pii-v1
Full breach record for Doxim →Doxim Inc. experienced a security incident on December 30, 2023, resulting in unauthorized access to files containing personal information of members of its B2B clients (credit unions). Files removed included names, addresses, account numbers, and Social Security numbers. Doxim took systems offline, notified law enforcement, and engaged forensic experts. No evidence of misuse was found. Doxim is offering 12 months of credit monitoring via Kroll.
Vermont clock✗ VT AG >45 bday22 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_46c60d7c1e44a8a7Delaware State AGfiled 2024-05-31Verified
- bd_c5e5240b71ffa580Indiana State AGfiled 2024-05-31Verified
- bd_da56de92f3ee4e5fMontana State AGfiled 2024-06-13(13d gap)Candidate
- bd_520aa0b12540d115California State AGfiled 2024-06-14(14d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 199d gap
- bd_db56f3d0be46da1aWashington State AGfiled 2024-12-11(194d gap)Verified
- bd_d6d4f9787b2aa530Oregon State AGfiled 2024-12-16(199d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-31-doxim-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2024
- Raw hash
- f59b78db6c94cdd500c5c2afb67779e0711dc1b108ae5cc1afaba2971141a6e3
Reporting entity
- Name
- Doximnorm: doxim
- Domain
- doxim.com
Victim entity
- Name
- Doximnorm: doxim
- Domain
- doxim.com
Incident
- Discovered
- Dec 30, 2023
- Materiality determined
- —
- Notification sent
- May 31, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(153 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.