IMA Diligence Services, LLC, a financial due diligence firm, experienced a data breach stemming from unauthorized access to a legacy file server between December 8 and December 16, 2025. The Genesis ransomware group claimed responsibility, posting 700 GB of stolen data on January 27, 2026. The company began notifying affected individuals via U.S. mail on May 29, 2026.
The breach impacted approximately 525,306 individuals across the United States. Exposed data types include Social Security numbers, driver’s license numbers, financial account information, credit/debit card numbers, medical and health insurance information, addresses, dates of birth, and government-issued IDs. For a limited number of individuals, passport numbers and taxpayer identification numbers were also exposed. The company is offering 12 months of free credit monitoring and identity restoration services through Cyberscout.
Details about data breaches can continue to emerge. Consumers are encouraged to remain vigilant.