Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
An Inter-Con Security Systems incident recorded by the Indiana Attorney General and associated with a separately verified HIBP corpus. [2]
Impact
Two people in the Indiana regulatory record and a much larger, separately quantified HIBP email-address corpus whose relationship is based on organization identity and temporal proximity. [1][2]
Documented data types include:
- Employment information — Employers and job titles listed by HIBP for the associated verified corpus; not categories stated in the Indiana registry row. [1]
- Names — Names listed by HIBP for the associated verified corpus; not a category stated in the Indiana registry row. [1]
- Contact information — Email addresses, phone numbers, and physical addresses listed by HIBP for the associated verified corpus; not categories stated in the Indiana registry row. [1]
A cited record reports 276,114 records (Unique email addresses represented in the verified HIBP corpus associated with Inter-Con Security; not an Inter-Con-confirmed number of people, employees, leads, contacts, or affected systems, and distinct from the regulator’s two-person notification population; as of 2026-08-05). [1][2]
A cited record reports 2 individuals (Total affected population in row 371 of the Indiana Attorney General registry; distinct from HIBP’s later unique-email corpus count; as of 2026-06-23). [1][2]
A cited record reports 2 individuals (Indiana residents affected in row 371; equal to, and therefore not additive to, the registry’s total affected count; as of 2026-06-23). [1][2]
Timeline
Documented event
Incident occurrence date in row 371 of the Indiana Attorney General registry.
[2]Public disclosure
Date the Indiana registry records that notification was sent; not necessarily a public announcement date.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
