What Happened in the IMA Diligence Services Data Breach?
IMA Diligence Services, LLC recently notified individuals about a data security incident that exposed personal information. The company provides professional services that involve analyzing data shared with it by clients. Because of this role, it held sensitive files belonging to people who may never have interacted with the company directly.
According to the notice, IMA Diligence learned on or about December 16, 2025 that certain files on a legacy server had become inaccessible. That server was managed by a third party and has since been decommissioned. After investigating, the company determined that an unauthorized actor had accessed the file server between December 8, 2025 and December 16, 2025. During that window, the intruder acquired certain files stored on the system.
Once IMA Diligence discovered the problem, it brought in outside cybersecurity specialists to investigate further. The goal was to determine the full nature and scope of the intrusion. As a result, the company conducted a detailed review of the affected files to identify exactly what information was exposed and which individuals were impacted.
This review took considerable time because of the volume and complexity of the data involved. However, the company says it worked to identify affected individuals so it could notify them directly. The unauthorized access to the network therefore occurred in December 2025, based on the timeline the company has disclosed.
Who was affected?
IMA Diligence has not publicly disclosed the exact number of individuals affected by this breach. Because the company performs data analysis services for other businesses, the people affected may not be its direct customers. Instead, they could be consumers, employees, or other individuals whose information was shared with IMA Diligence by a client for review or verification purposes.
The notice does not specify the geographic scope of those impacted, though the filing was made with the California Attorney General’s office. This suggests at least some affected individuals live in California. Since the exact population and any involvement of minors have not been disclosed, affected individuals should assume they could be impacted if they receive a notification letter.
What Information Was Potentially Exposed?
The notice confirms that files accessed during the breach contained each individual’s name along with other personal details. While the source material does not fully spell out every data category involved, breach notifications describing this kind of incident commonly include the following types of information.
- Full name
- Other personal identifiers contained in the affected files
- Information originally submitted to IMA Diligence for review or analysis on behalf of a client
Because IMA Diligence performs data analysis and diligence work, the files it holds can include sensitive personal or financial details depending on the nature of each client engagement. As a result, even a breach limited to a legacy server can expose meaningful personal information. This is especially true when the affected files were part of ongoing verification, investigation, or diligence work.
When names are exposed alongside other identifying details, individuals face a heightened risk of identity theft. Criminals can use stolen personal information to open new accounts, file fraudulent tax returns, or attempt account takeovers. In addition, exposed data can be combined with information from other breaches to build a more complete profile of a victim, making fraud attempts more convincing.
Beyond identity theft, affected individuals may also face an increased risk of targeted phishing attempts. Because attackers already possess real personal details, their scam messages can appear more legitimate. Therefore, vigilance becomes especially important in the months following a notification like this one.
What is the company doing?
Upon discovering the incident, IMA Diligence notified law enforcement and began an investigation to confirm what had happened. This response included verifying the security of its systems and reviewing the contents of the affected data for sensitive information. The company also worked to identify and notify individuals whose information appeared in the compromised files.
Going forward, IMA Diligence says it continues to review its policies, procedures, and processes around storing and accessing personal information. This is meant to reduce the likelihood of a similar incident happening again. The company also stated it will notify applicable regulatory authorities where necessary.
As an added precaution, IMA Diligence is offering twelve months of complimentary credit monitoring and identity restoration services through Cyberscout, a TransUnion company. Affected individuals must actively enroll in these services themselves, since the company cannot do so on their behalf. Instructions for activation were included with the notification letter.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Anyone who received a notice about this breach should check their credit reports regularly over the next several months. Experts generally recommend watching your accounts for at least 12 to 24 months after a breach like this one. This gives you time to catch new fraudulent accounts or unusual credit inquiries early.
You can request a free credit report from each of the three major credit bureaus. Reviewing these reports lets you spot unfamiliar accounts, unexpected credit inquiries, or errors that may signal fraud. If you notice anything suspicious, report it to the credit bureau and consider placing a fraud alert immediately.
Consider a Fraud Alert or Credit Freeze
Because the breach exposed your name alongside other personal information, placing a fraud alert on your credit file adds an extra layer of protection. A fraud alert requires lenders to verify your identity before opening new credit in your name. This step is free and generally lasts for one year, though it can be renewed.
For stronger protection, you can also request a credit freeze from each bureau. A freeze blocks new creditors from accessing your credit file entirely, which makes it much harder for identity thieves to open accounts. Although a freeze takes a few extra steps to lift when you need credit yourself, it offers one of the most effective defenses available.
Enroll in the Free Credit Monitoring Offered
IMA Diligence is offering twelve months of free credit monitoring and identity restoration through Cyberscout. This service can alert you the same day a change occurs on your credit file, allowing you to react quickly to any suspicious activity. Since this monitoring is provided at no cost, affected individuals should take advantage of it.
To enroll, follow the instructions included in the notification letter you received. Because the company cannot enroll you automatically, you must complete the sign-up process yourself. Doing so promptly ensures you get the full benefit of the monitoring period.
Stay Alert for Phishing and Scam Attempts
After a breach like this, scammers sometimes use exposed information to craft convincing phishing emails, texts, or phone calls. Be cautious of any unexpected messages asking you to confirm personal details or click a link. Legitimate companies rarely ask for sensitive information through unsolicited contact.
If you receive a suspicious message referencing this breach, avoid clicking links or providing information. Instead, contact the company directly using a verified phone number or website. This simple habit can prevent scammers from tricking you into handing over even more personal data.
More Information
Official data breach notification from Washington State Attorney General
Official data breach notification from California Attorney General
