Cyber Incident Victim: Inishowen Development Partnership
Date:
Mar 2023
Location:
Ireland
Summary
The Inishowen Development Partnership experienced a potential data breach stemming from a cyberattack on its software provider, Evide, which resulted in unauthorized access to data stored within the Impact Tracker platform. While the organization confirmed its own systems remained secure, limited contact details of program participants—excluding financial or medical information—were compromised through the third-party incident. IDP notified potentially affected individuals, engaged the Data Protection Commission, and emphasized vigilance against identity theft risks. Evide's investigation found no evidence of stolen data appearing on the dark web, but both entities advised assuming the information had been accessed. The incident occurred independently of IDP's internal security measures.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 4 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Inishowen Development Partnership (IDP) disclosed a potential data breach on March 1, 2023, following notification by its software partner, Evide, of a cyber-attack targeting Evide's systems. The attack compromised Evide’s Impact Tracker software platform, where IDP stored limited contact details of programme attendees and participants. IDP clarified that no financial records, medical data, or sensitive personal information resided on the platform, as its use had only recently commenced. Evide, a Derry-based company, confirmed unauthorized third-party access had resulted in data theft from their primary system but could not definitively confirm the full scope of exfiltrated information. Consequently, Evide advised all Impact Tracker customers, including IDP, to operate under the assumption their stored data had been stolen. IDP emphasized the breach originated entirely within Evide’s infrastructure, stating no compromise occurred within IDP’s internal networks or systems, which underwent review and were deemed secure.

The incident posed a heightened risk of identity theft for individuals whose contact details were potentially exposed, though Evide reported no evidence of the stolen data appearing on dark web markets during initial investigations. IDP promptly contacted affected clients directly, advising vigilance against suspicious communications and directing them to Garda Síochána fraud prevention resources. Ongoing coordination with Ireland’s Data Protection Commission and cybersecurity experts formed part of IDP’s response, alongside maintaining designated staff availability for public inquiries. Joint CEO Shauna McClenaghan expressed frustration over the breach despite IDP’s adherence to data protection standards, noting the limited data volume involved did not diminish organizational accountability. IDP continued monitoring internal systems while relying on Evide’s forensic investigation for further updates regarding data misuse or recovery efforts.
