HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIDENTITY_BASICEMPLOYMENTLowContained
Westat, Inc.
bd_241c67cca3274100 · schema v1 · pii pii-v1
Full breach record for Westat, Inc. →Westat, Inc. notified the New Hampshire AG of a data event involving the MOVEit Transfer tool. An unknown actor exploited a zero-day vulnerability to access the server between May 28-29, 2023, and exfiltrated HR files. Westat detected unusual activity on May 30, 2023. The breach affected 60 New Hampshire residents, exposing PII. Westat engaged forensic specialists, applied patches, and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed60 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/westat-20230721.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2023
- Raw hash
- 21afa29ccf393ce685ad819c10bfb3bb55367d21f393e961be7e4bfb1947741c
Reporting entity
- Name
- Westat, Inc.norm: westat
Victim entity
- Name
- Westat, Inc.norm: westat
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 60
- Data types
- PIIIDENTITY_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.