Sovos Compliance, LLC
bd_2644df19a41ec830 · schema v1 · pii pii-v1
Full breach record for Sovos Compliance, LLC →Sovos Compliance LLC notified the California Attorney General of a security event involving its MOVEit Transfer application. On May 31, 2023, Progress Software announced a previously unknown vulnerability in MOVEit. Unauthorized actors exploited this zero-day vulnerability to download files containing personal information of Sovos customers. The breach occurred on May 27, 2023. Sovos took the application offline, activated incident response, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_40393771a63e8372Oregon State AGfiled 2023-09-22Verified
- bd_7d54e64352e44cf5Vermont State AGfiled 2023-09-22Verified
- bd_9c65f917da81d4d8Maine State AGfiled 2023-09-22Verified
- bd_bfa8650066e49884Washington State AGfiled 2023-09-22Verified
Show 6 more filings ↓Show fewer ↑up to 30d gap
- bd_fd9a9a297311db80New Hampshire State AGfiled 2023-09-22Verified
- bd_1d16661cc5f0c5c2Maine State AGfiled 2023-09-05(17d gap)Verified
- bd_084e33a4c378d534Vermont State AGfiled 2023-08-23(30d gap)Verified
- bd_1263c3b040734745Delaware State AGfiled 2023-08-23(30d gap)Verified
- bd_186dbb4a134b0369New Hampshire State AGfiled 2023-08-23(30d gap)Verified
- bd_3d2bde1a29ed726eOregon State AGfiled 2023-08-23(30d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574062
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- 83c18204214bf26c4e09d5503f32fddcce11ef1cbac4c4e9ed61e63a9971a712
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Sep 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- CA 60-day late · 114d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Sep 22, 2023114d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.