CSIDB logo
Incident

Interactive Data

Incident posture

Attack window
Jun 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Interactive Data
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity researcher identified a fraud group exploiting compromised accounts at Interactive Data, a U.S. consumer data broker, to access detailed personal and financial records on Americans. The criminals used this stolen information to impersonate individuals and businesses, submitting fraudulent applications for COVID-19 economic relief programs. Their activities included illicitly obtaining small business loans through the U.S. Small Business Administration and filing fake unemployment insurance claims against multiple states, resulting in tens of millions of dollars stolen from federal and state treasuries. The group shared harvested data via an insecure email service, leveraging the company's breached systems to facilitate large-scale financial fraud.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In June 2020, a cybersecurity researcher discovered a criminal group exploiting compromised accounts at Florida-based data broker Interactive Data LLC (IDIdata.com) to harvest personal and financial records of U.S. consumers. The researcher, who monitored the group's communications for weeks, observed members sharing detailed records via an open email service that allowed public viewing of messages without authentication. The stolen data, bearing markers tracing back to Interactive Data's systems, included sensitive information enabling identity theft. The group, estimated to comprise hundreds of individuals, used this data to impersonate victims while submitting fraudulent applications for COVID-19 economic relief programs. Their activities targeted two primary channels: the U.S. Small Business Administration's small business loan programs and state-administered unemployment insurance systems.

The fraudulent schemes resulted in tens of millions of dollars stolen from federal and state treasuries before detection. KrebsOnSecurity verified the group's communications, which contained numerous records explicitly sourced from Interactive Data's platforms. Interactive Data, which markets access to a "massive data repository" on U.S. consumers to clients including law enforcement, had not publicly disclosed the account compromises at the time of reporting. The researcher proactively shared findings with state and federal authorities to disrupt the operations. The incident highlighted the exploitation of data broker systems to fuel large-scale financial fraud during pandemic relief efforts, though specific details regarding the number of affected individuals or Interactive Data's containment measures were not disclosed in available sources.

Sources

Sources available to members: 1 source.

CSIDB