CSIDB logo
Incident

Inishowen Development Partnership

Incident posture

Attack window
Mar 2023
Location
Ireland
Status
Historical
CIA posture
Available to members
Updated
2025-10-12 00:00

Linked entities

Victim
Inishowen Development Partnership
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Inishowen Development Partnership experienced a potential data breach stemming from a cyberattack on its software provider, Evide, which resulted in unauthorized access to data stored within the Impact Tracker platform. While the organization confirmed its own systems remained secure, limited contact details of program participants—excluding financial or medical information—were compromised through the third-party incident. IDP notified potentially affected individuals, engaged the Data Protection Commission, and emphasized vigilance against identity theft risks. Evide's investigation found no evidence of stolen data appearing on the dark web, but both entities advised assuming the information had been accessed. The incident occurred independently of IDP's internal security measures.

Motives

Detailed motive labels are available to members.

4 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Inishowen Development Partnership (IDP) disclosed a potential data breach on March 1, 2023, following notification by its software partner, Evide, of a cyber-attack targeting Evide's systems. The attack compromised Evide’s Impact Tracker software platform, where IDP stored limited contact details of programme attendees and participants. IDP clarified that no financial records, medical data, or sensitive personal information resided on the platform, as its use had only recently commenced. Evide, a Derry-based company, confirmed unauthorized third-party access had resulted in data theft from their primary system but could not definitively confirm the full scope of exfiltrated information. Consequently, Evide advised all Impact Tracker customers, including IDP, to operate under the assumption their stored data had been stolen. IDP emphasized the breach originated entirely within Evide’s infrastructure, stating no compromise occurred within IDP’s internal networks or systems, which underwent review and were deemed secure.

The incident posed a heightened risk of identity theft for individuals whose contact details were potentially exposed, though Evide reported no evidence of the stolen data appearing on dark web markets during initial investigations. IDP promptly contacted affected clients directly, advising vigilance against suspicious communications and directing them to Garda Síochána fraud prevention resources. Ongoing coordination with Ireland’s Data Protection Commission and cybersecurity experts formed part of IDP’s response, alongside maintaining designated staff availability for public inquiries. Joint CEO Shauna McClenaghan expressed frustration over the breach despite IDP’s adherence to data protection standards, noting the limited data volume involved did not diminish organizational accountability. IDP continued monitoring internal systems while relying on Evide’s forensic investigation for further updates regarding data misuse or recovery efforts.

Sources

Sources available to members: 1 source.

CSIDB