HackingTargetedIDENTITY_BASICLowContained
American Board of Internal Medicine
bd_e43308feb24723b9 · schema v1 · pii pii-v1
Full breach record for American Board of Internal Medicine →American Board of Internal Medicine (ABIM) notified consumers on July 25, 2023, of a data security incident detected on May 30, 2023. Suspicious activity was detected and stopped within ABIM's network. Forensic investigators determined that names, mailing addresses, and other personal information may have been exposed. ABIM engaged law enforcement and cybersecurity experts, implemented enhanced security safeguards, and provided affected individuals with 12-24 months of credit monitoring and identity theft protection services through IDX.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_155d60c8e451be00New Hampshire State AGfiled 2023-07-25Verified
- bd_3505d0ffe9192f4dMaine State AGfiled 2023-07-25Verified
- bd_9198b2a7adf48099California State AGfiled 2023-07-25Candidate
- bd_bfd56a6f20eb5a4fMontana State AGfiled 2023-07-25Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-25-american-board-internal-medicine-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 25, 2023
- Raw hash
- c8cf8fcb8091c045f47c98822ed686cbda51ce2b0816d0fed78b696c145a65ed
Reporting entity
- Name
- American Board of Internal Medicinenorm: american board of internal medicine
Victim entity
- Name
- American Board of Internal Medicinenorm: american board of internal medicine
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- Jul 25, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Working with law enforcement
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.