Clustered 6 filings across 4 jurisdictions · filing window Feb 1, 2024 → Mar 1, 2024. View entity profile → Other incidents for this victim →
incident inc_773ed406492840c6 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID · Financial account
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE OR WA
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Oct 30, 2023
Reported by WASHINGTON AG, OREGON AG filings
Nov 3, 2023
When the intrusion reportedly occurred, per the linked filings
Nov 3, 2023
Reported by DELAWARE AG, CALIFORNIA AG filings
Feb 13, 2024
Reported by OREGON AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Infosys McCamish Systems LLC (IMS) experienced a cybersecurity event on or around November 3, 2023, where an unauthorized third party accessed IMS systems. IMS provides services for deferred compensation plans, including those serviced by Bank of America. IMS notified Bank of America on November 24, 2023, that data concerning these plans may have been compromised. IMS retained a third-party forensic firm to investigate and assist with recovery, including containing malicious activity and rebuilding systems. IMS states it has found no evidence of continued threat actor access. The incident likely involved personal information of plan participants, including names, addresses, business emails, dates of birth, Social Security numbers, and account information. Bank of America is providing a complimentary two-year identity theft protection membership through Experian IdentityWorks to affected individuals.
Infosys McCamish Systems LLC (IMS) experienced a cybersecurity event on or around November 3, 2023, where an unauthorized third party accessed IMS systems. IMS provides services for deferred compensation plans, including those serviced by Bank of America. The incident resulted in the potential compromise of participant data, including names, addresses, SSNs, and account information. IMS retained forensic investigators, contained the threat, and Bank of America is offering two years of complimentary identity theft protection to affected participants.
Infosys McCamish Systems LLC, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-10-30 and filed notice on 2024-02-02. 857 Washington residents were affected. 95 days elapsed between awareness and notification. 1 days to identify the breach. 3 days to contain the breach.
Affected (this filing): 857
Infosys McCamish Systems LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2024-02-02. The breach occurred during 10/29/2023 - 11/2/2023. The breach was discovered on 10/30/2023. 57,028 individuals were affected. Notice was sent on 2/1/2024.
Affected (this filing): 57,028
Infosys McCamish Systems LLC (IMS) experienced a cybersecurity event on or around November 3, 2023, when an unauthorized third party accessed IMS systems. The incident potentially compromised deferred compensation plan information for participants in plans serviced by Bank of America, including names, addresses, dates of birth, Social Security numbers, and account information. IMS retained a forensic firm, contained the threat, and rebuilt systems. Bank of America is offering two years of complimentary identity theft protection via Experian.
Infosys McCamish Systems LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2024-03-01. The breach occurred during 10/29/2023 - 11/2/2023. The breach was discovered on 2/13/2024. 28,268 individuals were affected. Notice was sent on 3/1/2024.
Affected (this filing): 28,268