HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Sovos Compliance, LLC
bd_186dbb4a134b0369 · schema v1 · pii pii-v1
Full breach record for Sovos Compliance, LLC →Sovos Compliance, LLC notified New Hampshire regulators of a security event involving the MOVEit Transfer application. On May 31, 2023, unauthorized actors exploited a previously unknown vulnerability in the software to download personal information. Sovos took the application offline, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
This filing is one of 21 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_084e33a4c378d534Vermont State AGfiled 2023-08-23Verified
- bd_1263c3b040734745Delaware State AGfiled 2023-08-23Verified
- bd_3d2bde1a29ed726eOregon State AGfiled 2023-08-23Verified
- bd_1d16661cc5f0c5c2Maine State AGfiled 2023-09-05(13d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 30d gap
- bd_2644df19a41ec830California State AGfiled 2023-09-22(30d gap)Verified
- bd_40393771a63e8372Oregon State AGfiled 2023-09-22(30d gap)Verified
- bd_7d54e64352e44cf5Vermont State AGfiled 2023-09-22(30d gap)Verified
- bd_9c65f917da81d4d8Maine State AGfiled 2023-09-22(30d gap)Verified
- bd_bfa8650066e49884Washington State AGfiled 2023-09-22(30d gap)Verified
- bd_fd9a9a297311db80New Hampshire State AGfiled 2023-09-22(30d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sovos-compliance-20230823.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2023
- Raw hash
- e1a5cdacef5e1f02092dbe997f7c2e9bd3bd913f171befc087793d40172d3b7a
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.