LockBit ransomware attack stole data on millions of Infosys McCamish users
When LockBit ransomware affiliates struck Infosys McCamish Systems (IMS) in late 2023, they did not steal sensitive information on some 57,000 people, as was initially thought.
Instead, the threat actors stole valuable intel on more than six million people, a new report the IMS shared with the US authorities has said.
“With the assistance of third-party eDiscovery experts, retained through outside counsel, IMS proceeded to conduct a thorough and time-intensive review of the data at issue to identify the personal information subject to unauthorized access and acquisition and determine to whom the personal information relates,” the company said in its notification. “IMS has notified its impacted organizations of the Incident and of the compromise of any personal information pertaining to them.”
Identity theft galore
The type of information stolen from people varies from one individual to the next, but in general, the threat actors stole people’s Social Security Numbers (SSN), birth dates, medical information, biometric data, email addresses, passwords, Driver’s License numbers, state ID numbers, financial account information, payment card information, passport numbers, Tribal ID numbers, and US military ID numbers.
More than enough information to mount devastating phishing or identity theft attacks.
To combat the threat, IMS provided affected individuals with free identity protection and credit monitoring services through Kroll, for a period of two years.
Back in November 2023, Bank of America filed a data breach report with the Office of the Maine Attorney General, in which it said that the incident originated from an Infosys subsidiary. The report, filed on behalf of the Bank of America by an outside attorney, stated that Infosys McCamish Systems (IMS), a part of the Indian tech services giant, is an outside counsel for Bank of America.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The total number of people who were affected by the incident, which happened on October 29 2023 and discovered a day later, was said to be roughly 57,000, with the hackers stealing names (or other personal identifiers) and Social Security Numbers (SSN). The incident was described as “external system breach (hacking)”.
IMS did not say which companies were affected by this incident, other than Oceanview Life and Annuity Company.
Via BleepingComputer
More from TechRadar Pro
When LockBit ransomware affiliates struck Infosys McCamish Systems (IMS) in late 2023, they did not steal sensitive information on some 57,000 people, as was initially thought. Instead, the threat actors stole valuable intel on more than six million people, a new report the IMS shared with the US authorities has…
Recent Posts
- How to watch World Cup final replay – it’s spoiler-free
- The Kodak EC35 is a pocketable, beginner-friendly 35mm film camera
- This unpronounceable series of glyphs is an incredible side project from Kieran Hebden (aka Four Tet)
- Kodak EC35 is a dirt-cheap point-and-shoot film camera
- NASA shares beautiful timelapse of the Psyche spacecraft’s view over Mars
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023