HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICLowContained
Fiduciary Outsourcing
bd_21222e64aab559c0 · schema v1 · pii pii-v1
Full breach record for Fiduciary Outsourcing →Fiduciary Outsourcing LLC notified consumers of a data breach stemming from a zero-day vulnerability in the MOVEit Transfer solution exploited by unauthorized actors. The incident resulted in the potential exfiltration of names. The company engaged third-party investigators and offered free credit monitoring services to affected individuals.
Vermont clock✓ VT AG ≤14 bday18 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1c16336e28435147Maine State AGfiled 2024-03-19Candidate
- bd_67d4bf413a4dd154Montana State AGfiled 2024-03-19Verified by operator
- bd_b867e887cbae7fb7California State AGfiled 2024-03-19Verified
- bd_fd49051419592048Indiana State AGfiled 2024-03-19Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-03-19-fiduciary-outsourcing-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2024
- Raw hash
- fbd67465c8c8b59f8896a15ed8093c3be1a89b70b1a7a09db28c856410d01bf8
Reporting entity
- Name
- Fiduciary Outsourcingnorm: fiduciary outsourcing
Victim entity
- Name
- Fiduciary Outsourcingnorm: fiduciary outsourcing
Incident
- Discovered
- Mar 1, 2024
- Materiality determined
- —
- Notification sent
- Mar 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.