[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f14utkfnz89flf":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825236","Imavex","Imavex Data Breach","imavex","imavex.com","2021-08-20T00:00:00.000Z","2021-08-26T05:48:29.000Z","2026-07-29T14:12:58.498Z","Archived official notice and verified breach record","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20210827031447\u002Fhttps:\u002F\u002Fwww.imavex.com\u002Fbreach-information\u002F",[15],878209,"known",null,"email_identifiers","High",[23,24,25,26,27,28,29,30,31],"Email addresses","Genders","Names","Partial credit card data","Passwords","Phone numbers","Physical addresses","Purchases","Usernames","\u003Cp>\u003Cstrong>The Imavex 2021 data breach\u003C\u002Fstrong> is the incident in which the company said an attacker gained privileged access to one of its systems on 20 August 2021 and obtained a copy of a production database. The first-party notice preserved by the Wayback Machine says the database copy was published on hacker forums. A verified breach record reports 878,209 unique email addresses associated with the event; this is not a count of files, forms, or total rows.\u003C\u002Fp>\n\n\u003Cp>The event was not limited to Imavex account records. The verified record says the dataset also included hundreds of thousands of form submissions and orders processed through Imavex customers. An email match therefore does not by itself establish the contents of a particular form or order or that every listed field applied to the same person.\u003C\u002Fp>\n\n\u003Ch2>What information may have been involved?\u003C\u002Fh2>\n\u003Cp>The sources list email addresses, names, usernames, password material, phone numbers, physical addresses, gender information, purchase information, and some form contents. Some records also contained the last four card digits and expiration date. Imavex's notice says its systems did not store plaintext passwords or full credit card numbers. Card security codes, bank accounts, Social Security numbers, and government identification are not confirmed fields for this event.\u003C\u002Fp>\n\n\u003Ch2>Organization response and safe next steps\u003C\u002Fh2>\n\u003Cp>The verified record says the affected legacy system was sunset in January 2024 and the related customer data remaining in that system was deleted. That action cannot retrieve copies taken earlier. If a password used at the time was reused on another service, create a unique password there and enable multifactor authentication. Unexpected support, refund, and payment messages containing an address, phone number, order detail, or partial card data should be verified through a known official channel. Because the former Imavex domain now redirects to a different brand, historical company and incident links point to archived copies.\u003C\u002Fp>","","Imavex 2021 Data Breach (878.2 Thousand Email Identifiers)","The Imavex breach included 878,209 unique email addresses. Review the account, form, order, and partial-card data scope.","\u002Fuploads\u002Flogo\u002Fimavex_com.webp",false,{"name":7,"sector":39,"country":40,"website":10,"websiteArchiveUrl":41,"websiteStatus":42,"websiteCheckedAt":19},"Website Development","United States","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20210927162215\u002Fhttps:\u002F\u002Fwww.imavex.com\u002F","archived"]