Confirmed breach. Intrusion Dec 4, 2024–Dec 9, 2024, discovered Dec 9, 2024 — the first regulatory filing landed 343 days later (flagged late). 1 individuals reported across the linked filings.
incident inc_ae5586d587764a0f · merge_method human · confidence 100%
Litigation Timing
Supplemental
Notification delay
343days
Discovered → first regulatory filing
Discovery variance
0days
Range of discovered_at dates across filings
Leak precedence
Regulatory clocksMaine✗ ME AG >90d · 343dVermont✗ VT AG >45 bdayCalifornia✗ CA 60-day late · 305dFull clock table in Litigation Timeline
Leak SiteState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedakira
343days
Gap between first leak claim and first regulatory filing
Filing span
375days
Time between earliest and latest filing
Not recorded for this incident
Materiality delta · SEC filing delay — no SEC 8-K in this cluster.
high sensitivity
Affected (total reported)
1
Data types
4
PII · Identity (basic) · Government ID
Jurisdictions
4
CA ME VT
Linked filings
5
Leak Site · State AG
Sensitive data
identity_government
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Dec 4, 2024 → Dec 9, 2024
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Dec 9, 2024
Reported by MAINE AG, VERMONT AG, CALIFORNIA AG filings
🌐GLOBALClaimed by AkiraFirst sightinglinked via operator-confirmed · 100%
Drivestream is a management and IT consulting firm specializing i
n migrating the enterprise business processes of large and medium
sized businesses to the Cloud.
We are ready to upload more than 80 GB of private corporate docum
ents including: SSNs, family contacts, contact numbers and e-mail
addresses of employees and customers, driver licenses, passports
etc.
30 days
🌐GLOBALClaimed by Akiralinked via shared-victim match · 100%
Drivestream is a management and IT consulting firm specializing i
n migrating the enterprise business processes of large and medium
sized businesses to the Cloud.
We are ready to upload more than 80 GB of private corporate docum
ents including: SSNs, family contacts, contact numbers and e-mail
addresses of employees and customers, driver licenses, passports
etc.
313 days
Most recent
3 State AG filingsNov 17, 2025 – Dec 19, 2025ExpandCollapse
MEVTCA
Maine State AG
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Drivestream Inc., an IT services company assisting businesses with Oracle data migration, experienced an external system breach between December 4–9, 2024. An unauthorized actor accessed and potentially exfiltrated data including names, Social Security numbers, and financial account information. One Maine resident was affected. The company engaged third-party forensic investigators, notified law enforcement, and offered 12 months of credit monitoring through Epiq.
Affected (this filing): 1
ME AG >90d · 343dME resident >180d · 343dLeak >180d
🍁Vermont State AGLeaked → filing gap · 12 molinked via operator-confirmed · 100%
Drivestream Inc. notified consumers of a data breach occurring between Dec 4-9, 2024, where an unauthorized actor accessed systems storing employee data during an HCM migration. Impacted data included names combined with government identifiers (SSN, DOB, driver's license). Drivestream reported the incident to law enforcement, is cooperating with the investigation, and is offering credit monitoring services.
VT AG >45 bdayLeak >180d
🐻California State AGLeaked → filing gap · 1 yrlinked via cross-source match · 100%
Drivestream, Inc. notified the California AG of an incident where an unauthorized actor accessed systems between Dec 4-9, 2024, and downloaded files containing employee data (including SSNs) during an HCM migration. Drivestream discovered the activity on Dec 9, 2024. The company engaged law enforcement, secured systems, and is offering credit monitoring. No evidence of misuse was found.