HackingVulnerability ExploitSupply Chain (Dependency)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCVE-2023-34362MediumContained
Fiduciary Outsourcing
bd_1c16336e28435147 · schema v1 · pii pii-v1
Full breach record for Fiduciary Outsourcing →Fiduciary Outsourcing, LLC experienced a data breach due to the MOVEit Transfer vulnerability exploit, impacting six Maine residents. The breach, which occurred on May 31, 2023, and was discovered on March 1, 2024, resulted in the compromise of names and Social Security numbers. The company provided written notification to affected individuals on March 19, 2024, and offered 12 months of identity theft protection services through CyberScout.
Maine clockDiscovered Mar 1, 2024 → Filed with AG Mar 19, 202418d ✓ ME AG ≤30d18 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_21222e64aab559c0Vermont State AGfiled 2024-03-19Verified
- bd_67d4bf413a4dd154Montana State AGfiled 2024-03-19Verified by operator
- bd_b867e887cbae7fb7California State AGfiled 2024-03-19Verified
- bd_fd49051419592048Indiana State AGfiled 2024-03-19Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a8172236-e484-4e55-b71c-442872161634.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2024
- Raw hash
- da10f3cd54551d473d01a269b58ddc930d883ad804a996fdf34683f36d3a4dfc
Reporting entity
- Name
- Fiduciary Outsourcingnorm: fiduciary outsourcing
Victim entity
- Name
- Fiduciary Outsourcingnorm: fiduciary outsourcing
Incident
- Discovered
- Mar 1, 2024
- Materiality determined
- —
- Notification sent
- Mar 19, 2024
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- External
- CVE references
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 18d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 1, 2024→ Filed with AG: Mar 19, 202418d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.