State of Maine
bd_0c414cef662e480b · schema v1 · pii pii-v1
Full breach record for State of Maine →The State of Maine notified the New Hampshire Attorney General on November 15, 2023, regarding a cybersecurity incident involving its MOVEit file transfer software. The breach exploited a zero-day vulnerability (CVE-2023-35174) in the software, leading to unauthorized access and exfiltration of personal data affecting approximately 1.3 million individuals. The State became aware of the vulnerability on May 31, 2023, when a patch was released, but did not discover the breach until later. Affected data included Social Security numbers, taxpayer information, and other personally identifiable information. The State has begun notifying affected individuals.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_9fdd1746eaefe173HHS OCRfiled 2023-11-16(1d gap)Verified
- bd_54ab15a9f1f46a49Washington State AGfiled 2023-11-13(2d gap)Verified
- bd_3234f2a5a49275f0Vermont State AGfiled 2023-11-09(6d gap)Verified
- bd_bb9048f3d846f18fMontana State AGfiled 2023-11-09(6d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 12d gap
- bd_c6058d3ab49a2b3cMaine State AGfiled 2023-11-09(6d gap)Verified
- bd_9f3c12779b714b64California State AGfiled 2023-11-27(12d gap)Verified
- bd_d9f19ada2e1cd45aOregon State AGfiled 2023-11-27(12d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/state-of-maine-20231115.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 15, 2023
- Raw hash
- c45be49d9f84d3848f6579332346f85e195f9bda34bb4f67ae7dd09f63b5dab3
Reporting entity
- Name
- State of Mainenorm: state of maine
Victim entity
- Name
- State of Mainenorm: state of maine
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Nov 15, 2023
- Affected individuals
- 1,300,000
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 24 weeks(168 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.