IMA Diligence Services
Incident posture
Linked entities
- Victim
- IMA Diligence Services
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
IMA Diligence Services notified over 525,000 individuals that their personal information was stolen after a legacy server managed by a third party became inaccessible and attackers accessed the server and exfiltrated files containing names, addresses, Social Security numbers, driver’s license numbers, account numbers, credit card numbers, medical and health insurance information, and in some cases passport numbers and taxpayer identification numbers. The company told the Indiana Attorney General’s Office that 525,306 people were affected and is providing twelve months of free credit monitoring and identity restoration services, while the breach was claimed by the Genesis ransomware group, which added the firm to its leak site alleging theft of seven hundred gigabytes of data including personal and business files. A subsidiary of IMA Financial Group that provides financial consulting for acquisitions, mergers and other corporate transactions, it was previously known as RedRidge Diligence Services.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In mid‑December 2025, IMA Diligence Services became aware that a legacy server managed by a third‑party provider had become inaccessible. Upon discovering the issue, the company promptly notified law enforcement and initiated an internal investigation to determine the nature and scope of the incident. IMA Diligence Services engaged external cybersecurity experts to assist with the investigation. The experts determined that unauthorized actors had accessed the server between December 8 and December 16, 2025, and had exfiltrated certain files from the system.
After reviewing the exfiltrated data, IMA Diligence Services identified that the compromised information included personal details such as names, addresses, Social Security numbers, and driver’s license numbers. The breach also exposed financial data, including bank account numbers and credit card numbers, as well as medical and health insurance information. In some cases, passport numbers and taxpayer identification numbers were among the stolen records. Based on its assessment, the company reported to the Indiana Attorney General’s Office that 525,306 individuals were affected and began offering them twelve months of free credit monitoring and identity restoration services.
The company’s public notice did not name the threat actor, but the Genesis ransomware group later claimed responsibility for the attack. In late January 2026, Genesis added IMA Diligence Services to its Tor‑based leak site, asserting that it had stolen approximately 700 gigabytes of data comprising personal information, business documents, and confidential files. IMA Diligence Services operates as a subsidiary of IMA Financial Group, providing financial consulting services for acquisitions, mergers, and other corporate transactions. Founded in 2009, the firm was previously known as RedRidge Diligence Services.
Sources
Sources available to members: 1 source.