Indico Data
ent_61963cfd486798dc55a3a8c8
Disclosures
7
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,840
nationwide · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Indico Data
- Normalized
- indico data— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- indicodata.ai
Disclosure history (7)newest first
- Texas State AGas victim2026-09-01
Indico Data Solutions based in Boston, Massachusetts, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-05-07 and reported on 2026-09-01. 2,128 Texas residents were affected. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
- Massachusetts State AGas victim2026-09-01
Indico Data Solutions experienced a cybersecurity incident involving unauthorized access to online repositories containing customer information. The company determined on May 7, 2026, that it had suffered the incident. On August 3, 2026, it confirmed that personal information, including names, Social Security Numbers, Account Numbers, and Institution Names, was present in the affected repositories. Indico implemented incident response protocols, secured its environment, and engaged external cybersecurity specialists. Remediation steps included rotating access credentials, implementing additional monitoring tools, and tightening access controls. Affected individuals are offered 24 months of credit monitoring and fraud assistance services.
- California State AGas victim2026-08-27
Indico Data Solutions experienced a cybersecurity incident involving unauthorized access to online repositories containing customer information. The breach occurred on May 5, 2026, and was discovered on May 7, 2026. Affected data includes names, Social Security Numbers, account numbers, and institution names. The company implemented incident response protocols, secured its environment, and engaged external cybersecurity specialists. Remediation measures included rotating credentials, implementing additional monitoring, and tightening access controls. Credit monitoring and fraud assistance services were offered to affected individuals.
- Nebraska State AGas victim2026-08-27
Indico Data Solutions, Inc. submitted a supplemental data breach notification to the Nebraska Attorney General on August 27, 2026. Acting at the request of its customers, Indico notified an additional 58 Nebraska residents of a prior data security incident. Notification letters were mailed on August 27, 2026. This filing supplements a previous notification sent on July 16, 2026.
- Texas State AGas victim2026-08-10
Indico Data Solutions based in Boston, Massachusetts, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-05-07 and reported on 2026-08-10. 855 Texas residents were affected. Types of information involved: Name of individual;Address;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
- MASSACHUSETTSHHS OCRas victim2026-08-07
Indico Data Solutions, Inc. reported to HHS on 2026-08-07 a Hacking/IT Incident affecting 4840 individuals. Breached information located on Network Server.
- Nebraska State AGas victim2026-07-16
Indico Data Solutions reported a cybersecurity incident to the Nebraska Attorney General on July 16, 2026. The company discovered unauthorized access to online repositories containing customer information on May 7, 2026. The incident affected 4 Nebraska residents, exposing names, addresses, and Social Security numbers. Indico rotated credentials, enhanced monitoring, and offered 12 months of credit monitoring via Cyberscout.