HackingProfessional ServicesProfessional ServicesCapture Stored DataData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTFINANCIAL_CREDENTIALSMediumResolved
The CCIM Institute
bd_ea4c8e5ac5ff7440 · schema v1 · pii pii-v1
Full breach record for The CCIM Institute →The CCIM Institute (Chicago, IL) reported an external hacking incident in which an unknown actor accessed and copied files from its computer systems between July 12–13, 2024. The breach was identified on July 15, 2024, but review of affected data was completed January 3, 2025. Compromised information includes names, Social Security numbers, and payment card information. Two Maine residents were affected out of 1,754 total. Affected individuals were offered 24-month Experian credit monitoring.
Maine clockDiscovered Jan 3, 2025 → Filed with AG Jan 24, 202521d ✓ ME AG ≤30d21 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_32e0da482b2a4a09New Hampshire State AGfiled 2025-01-24Verified
- bd_da3b0c62a4cd5246Indiana State AGfiled 2025-01-24Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/f21d7bfd-3f57-4119-96e3-ff2e67893fdf.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 24, 2025
- Raw hash
- f0e57910463da31243507d6083d76075490c6fcce381882130ac579da23e96c9
Reporting entity
- Name
- The CCIM Institutenorm: the ccim institute
- Domain
- ccim.com
- Industry
- Other Commercial
Victim entity
- Name
- The CCIM Institutenorm: the ccim institute
- Domain
- ccim.com
- Industry
- Other Commercial
- Industry
- Professional Servicesllm
Incident
- Discovered
- Jan 3, 2025
- Materiality determined
- —
- Notification sent
- Jan 24, 2025
- Affected individuals
- 2
- Data types
- PIIIDENTITY_GOVERNMENTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 3, 2025→ Filed with AG: Jan 24, 202521d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.