Diligent
ent_f62f34616f03353e0f482f06
Disclosures
7
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,184
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Diligent
- Normalized
- diligent— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 984500CA0960470D7B49
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- diligent.com
Disclosure history (7)newest first
- Montana State AGas victim2023-06-09
Leidos, Inc. notified affected individuals of a data breach involving its third-party vendor Diligent Corporation. An unauthorized individual exploited vulnerabilities in Diligent's ECMS platform to access documents containing personal information. The incident occurred between September and October 2022 and was discovered in November 2022. Leidos offered two years of credit monitoring.
- Montana State AGas reporting2023-02-02
Diligent Corporation notified Montana residents that Steele Compliance, a subsidiary acquired in Feb 2021, suffered unauthorized network access starting May 21, 2022. Diligent detected the breach on May 23, 2022, and contained it by May 24. Later, files posted by the attacker revealed additional personal data was accessed. Diligent engaged outside experts, enhanced security controls, and offered 24 months of credit monitoring.
- Vermont State AGas reporting2023-02-02
Diligent Corporation notified consumers that Steele Compliance, a subsidiary acquired in Feb 2021, suffered unauthorized network access starting May 21, 2022. The incident was contained by May 24, 2022, but data exfiltration was confirmed later when files were posted externally. Affected data included PII and government IDs. Diligent engaged outside experts, enhanced security controls, and provided 24 months of credit monitoring.
- California State AGas victim2023-02-01
Diligent Corporation experienced unauthorized access to a network supporting its subsidiary, Steele Compliance, between May 21 and May 24, 2022. The security team detected the incident on May 23, 2022, and contained it by May 24, 2022. The breach involved human resources records, including names, email addresses, mailing addresses, and Social Security numbers. Diligent engaged outside experts, enhanced security controls, and offered 24 months of credit monitoring to affected individuals.
- Indiana State AGas victim2022-06-22
Diligent Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2022-05-21 and was reported on 2022-06-22. 1 Indiana residents were affected. 1,184 individuals affected in total.
- Massachusetts State AGas victim2022-06-22
Diligent Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-06-22. 11 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-06-22
Diligent Corporation reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred between May 21, 2022, and May 24, 2022. The breach was discovered on May 23, 2022. The compromised information includes names or other personal identifiers in combination with Social Security Numbers. Three Maine residents were among the 1,184 individuals affected. In response, Diligent offered 24 months of credit monitoring and identity theft protection services through Experian IdentityWorks to those impacted.