Quixtar Inc. notified New Hampshire Attorney General Kelly Ayotte of a security incident discovered on May 27, 2008. Fraudsters accessed Independent Business Owner (IBO) accounts using credentials obtained from an external website (phishing). The intruders changed bank account details to divert bonus payments. Quixtar scrambled passwords on June 4, 2008, and sent notification letters on June 11, 2008. No SSN, credit card, or bank account numbers were accessed. Quixtar cooperated with the FBI. The investigation was active as of the filing date.