Sovos Compliance, LLC
bd_2644df19a41ec830 · schema v1 · pii pii-v1
Full breach record for Sovos Compliance, LLC →4 incidents on fileSovos Compliance LLC notified the California Attorney General of a security event involving its MOVEit Transfer application. On May 31, 2023, Progress Software announced a previously unknown vulnerability in MOVEit. Unauthorized actors exploited this zero-day vulnerability to download files containing personal information of Sovos customers. The breach occurred on May 27, 2023. Sovos took the application offline, activated incident response, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 27, 2023
Begins
May 31, 2023
Discovered
Sep 22, 2023
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Oregon State AGbd_40393771a63e83722023-09-22Verified
- Vermont State AGbd_7d54e64352e44cf52023-09-22Verified
- Maine State AGbd_9c65f917da81d4d82023-09-22Verified
- Washington State AGbd_bfa8650066e498842023-09-22Verified
Show 6 more filings ↓Show fewer ↑up to 30d gap
- New Hampshire State AGbd_fd9a9a297311db802023-09-22Verified
- Maine State AGbd_1d16661cc5f0c5c22023-09-05 · +17dVerified
- Vermont State AGbd_084e33a4c378d5342023-08-23 · +30dVerified
- Delaware State AGbd_1263c3b0407347452023-08-23 · +30dVerified
- New Hampshire State AGbd_186dbb4a134b03692023-08-23 · +30dVerified
- Oregon State AGbd_3d2bde1a29ed726e2023-08-23 · +30dVerified
Showing first 10 of 21 linked disclosures.
Filing propagation · 11 filings · 7 states
View merged incident ↗Pattern: first filing Aug 23 (VT), last Sep 22 (CA) — a 30-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 21 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.