HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
American Board of Internal Medicine
bd_155d60c8e451be00 · schema v1 · pii pii-v1
Full breach record for American Board of Internal Medicine →American Board of Internal Medicine (ABIM) notified the NH Attorney General of a data security incident involving its third-party vendor, Progress Software, via the MOVEit Transfer vulnerability. ABIM detected suspicious activity on May 30, 2023, and confirmed unauthorized access to some data on May 31, 2023. 21 New Hampshire residents were affected. ABIM engaged forensic investigators, worked with law enforcement, and offered credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3505d0ffe9192f4dMaine State AGfiled 2023-07-25Verified
- bd_9198b2a7adf48099California State AGfiled 2023-07-25Candidate
- bd_bfd56a6f20eb5a4fMontana State AGfiled 2023-07-25Verified
- bd_e43308feb24723b9Vermont State AGfiled 2023-07-25Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/american-board-internal-medicine-20230725.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 25, 2023
- Raw hash
- a0e30d48985d244d3ffbd7017a0245a225f192188dd63a0118b7dbf1bd2ff448
Reporting entity
- Name
- American Board of Internal Medicinenorm: american board of internal medicine
Victim entity
- Name
- American Board of Internal Medicinenorm: american board of internal medicine
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- Jul 25, 2023
- Affected individuals
- 21
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Third party
- via Progress Software
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.