Infosys Limited's U.S. subsidiary, Infosys McCamish Systems LLC, experienced a significant data breach involving unauthorized access and data exfiltration that compromised personal information of approximately 6.5 million individuals in the U.S. The incident, claimed by the LockBit ransomware group, led to encryption of corporate systems and a ransom demand. Personal data leaked included names, Social Security numbers, financial accounts, and medical data of clients from major financial institutions. The breach led to substantial financial loss for Infosys, including $38 million in remediation costs and reputational damage.
Source: https://cybersecuritynews.com/infosys-agrees-to-17-5-million-settlement/
TPRM report: https://scoringcyber.rankiteo.com/company/infosys
"id": "inf121032125",
"linkid": "infosys",
"type": "Breach",
"date": "3/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '6.5 million',
'industry': 'Technology',
'location': 'U.S.',
'name': 'Infosys McCamish Systems LLC',
'type': 'Subsidiary'}],
'attack_vector': 'Unauthorized Access, Data Exfiltration',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '6.5 million',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal information',
'Financial data',
'Medical data']},
'description': 'Infosys McCamish Systems LLC experienced a significant data '
'breach involving unauthorized access and data exfiltration '
'that compromised personal information of approximately 6.5 '
'million individuals in the U.S. The incident, claimed by the '
'LockBit ransomware group, led to encryption of corporate '
'systems and a ransom demand. Personal data leaked included '
'names, Social Security numbers, financial accounts, and '
'medical data of clients from major financial institutions.',
'impact': {'brand_reputation_impact': 'Yes',
'data_compromised': ['Names',
'Social Security numbers',
'Financial accounts',
'Medical data'],
'financial_loss': '38 million',
'systems_affected': 'Corporate systems'},
'motivation': 'Financial Gain',
'ransomware': {'data_encryption': 'Yes',
'data_exfiltration': 'Yes',
'ransom_demanded': 'Yes',
'ransomware_strain': 'LockBit'},
'threat_actor': 'LockBit ransomware group',
'title': 'Infosys McCamish Systems Data Breach',
'type': 'Data Breach, Ransomware'}