Article Details
Scrape Timestamp (UTC): 2024-06-28 18:10:40.882
Original Article Text
Click to Toggle View
Infosys McCamish says LockBit stole data of 6 million people. Infosys McCamish Systems (IMS) disclosed that the LockBit ransomware attack it suffered earlier this year impacted sensitive information of more than six million individuals. IMS is a multinational corporation that provides business consulting, information technology, and outsourcing services. It specializes in covering the needs of firms in the insurance and financial services industries. The company has a significant presence in the U.S., serving large financial institutions such as the Bank of America and seven out of the top ten insurers in the country. In February 2024, IMS informed the public that it had been hit by a ransomware in November 2023, which resulted in the compromise of the personal data of about 57,000 Bank of America customers. At the time, LockBit claimed the attack and said that it had encrypted 2,000 computers on the IMS network. In a new notification shared with the authorities in the U.S., IMS now says the total number of people affected by the November 2023 ransomware attack is a little over 6 million. “With the assistance of third-party eDiscovery experts, retained through outside counsel, IMS proceeded to conduct a thorough and time-intensive review of the data at issue to identify the personal information subject to unauthorized access and acquisition and determine to whom the personal information relates,” reads the notification. “IMS has notified its impacted organizations of the Incident and of the compromise of any personal information pertaining to them.” The data confirmed as compromised varies from one individual to another but includes the following: To mitigate the risk from the exposure, the notification letters enclose instructions on how to access a free-of-charge, two-year identity protection and credit monitoring service through Kroll. IMS has not disclosed which of its clients were impacted, except for Oceanview Life and Annuity Company (OLAC), an Arizona-based fixed and fixed-indexed annuities provider that secures retirement income for policyholders. IMS’ notice mentions that the list of impacted data owners, currently only listing OLAC, may be supplemented on a rolling basis as more customers request to be named in the filing.
Daily Brief Summary
Infosys McCamish Systems (IMS) revealed a LockBit ransomware attack affected over six million individuals.
Initially reported in February 2024, the attack occurred in November 2023, impacting sensitive data including 57,000 Bank of America customers.
LockBit encrypted 2,000 computers within the IMS network during the incident.
Following a detailed review by third-party eDiscovery experts, IMS confirmed the extensive unauthorized data access.
Personal data compromised in the breach varies, necessitating personalized notification and identity protection services offered by IMS through Kroll.
Only Oceanview Life and Annuity Company has been publicly named as one of the affected clients, with potential additional disclosures pending.
IMS is a major service provider in the insurance and financial sectors, indicating a significant impact on these industries due to the breach.