MAXIMUS, Inc.
bd_08c05ac3d136140d · schema v1 · pii pii-v1
Full breach record for MAXIMUS, Inc. →7 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Cl0p on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Moving people forward - Maximus
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jul 26, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- California State AGbd_bf25ea19ea12a1242023-08-18 · +23dVerified
- Indiana State AGbd_45d3fdf48f1c933d2023-08-24 · +29dVerified by operator
- Vermont State AGbd_67d6131ab83daa012023-08-25 · +30dVerified by operator
- Delaware State AGbd_97027e573fc51e132023-08-25 · +30dVerified by operator
Show 6 more filings ↓Show fewer ↑up to 168d gap
- Washington State AGbd_d4deac1eb085d27a2023-08-25 · +30dVerified
- New Hampshire State AGbd_fe9387821fda92642023-08-25 · +30dVerified by operator
- Hawaii State AGbd_d3d3db6e2dd7a7a82023-08-26 · +31dVerified by operator
- Oregon State AGbd_4a2584ab84dfe0f12023-08-29 · +34dVerified by operator
- South Carolina State AGbd_a90da3e7c4e0509c2023-08-29 · +34dVerified
- Idaho State AGbd_5312733f463970a32024-01-10 · +168dVerified by operator
Showing first 10 of 16 linked disclosures.
Filing propagation · 11 filings · 10 states
View merged incident ↗Pattern: first filing Jul 26, last Jan 10 (ID) — a 168-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 16 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.