HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Nuance Communications, Inc
bd_119ca48980839f9b · schema v1 · pii pii-v1
Full breach record for Nuance Communications, Inc →Nuance Communications, Inc. disclosed a security incident involving its third-party vendor, Progress Software's MOVEit Transfer software. An unauthorized third party exploited a previously unknown vulnerability (zero-day) between May 28-29, 2023, to exfiltrate data. Nuance confirmed the breach on July 11, 2023, and notified affected individuals starting August 1, 2023. Affected data included names, dates of birth, medical record numbers, gender, and radiology study details. Nuance secured servers, engaged cybersecurity experts, and notified law enforcement.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_b80d8c8f8a2bace4Delaware State AGfiled 2023-09-18Verified
- bd_61e841c1c6509034Oregon State AGfiled 2023-09-19(1d gap)Verified
- bd_2d18f75acad25ac9Maine State AGfiled 2023-09-15(3d gap)Candidate
- bd_42ba23005cabceb8New Hampshire State AGfiled 2023-09-15(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- bd_829cc01dc8d0b732California State AGfiled 2023-09-15(3d gap)Verified
- bd_f82949cd77b8e1acMontana State AGfiled 2023-09-15(3d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/10/Nuance-Notice-Template-gen.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 18, 2023
- Raw hash
- 3a79ddeca41f49cf7b151b3bd3027f3fc11c10c0ef5ebd56c3ff66e1c28f5a45
Reporting entity
- Name
- Nuance Communications, Incnorm: nuance communications
Victim entity
- Name
- Nuance Communications, Incnorm: nuance communications
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 1, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.