HackingVulnerability ExploitData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Sovos Compliance, LLC
bd_1263c3b040734745 · schema v1 · pii pii-v1
Full breach record for Sovos Compliance, LLC →Sovos Compliance LLC disclosed a security event involving the MOVEit Transfer application vulnerability discovered May 31, 2023. Unauthorized actors exploited the vulnerability to exfiltrate personal information, including government IDs and basic identity data. Sovos took the application offline, retained experts, notified law enforcement, and offers two years of credit monitoring via Kroll.
This filing is one of 21 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_084e33a4c378d534Vermont State AGfiled 2023-08-23Verified
- bd_186dbb4a134b0369New Hampshire State AGfiled 2023-08-23Verified
- bd_3d2bde1a29ed726eOregon State AGfiled 2023-08-23Verified
- bd_1d16661cc5f0c5c2Maine State AGfiled 2023-09-05(13d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 30d gap
- bd_2644df19a41ec830California State AGfiled 2023-09-22(30d gap)Verified
- bd_40393771a63e8372Oregon State AGfiled 2023-09-22(30d gap)Verified
- bd_7d54e64352e44cf5Vermont State AGfiled 2023-09-22(30d gap)Verified
- bd_9c65f917da81d4d8Maine State AGfiled 2023-09-22(30d gap)Verified
- bd_bfa8650066e49884Washington State AGfiled 2023-09-22(30d gap)Verified
- bd_fd9a9a297311db80New Hampshire State AGfiled 2023-09-22(30d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/Delaware-Exhibit-A-and-B.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2023
- Raw hash
- b039e91110a26d4821ada68c606a6143028104fffe4dbd835060ec4c039e7d16
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.