HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
M. Arthur Gensler Jr. & Associates, Inc.
bd_2d48359ec9022072 · schema v1 · pii pii-v1
Full breach record for M. Arthur Gensler Jr. & Associates, Inc. →Gensler experienced a data breach via a third-party software vendor, Progress MOVEit, between May 27 and May 31, 2023. An unauthorized party accessed and copied files containing names, Social Security numbers, and dates of birth of US-based employees. Gensler disabled access, patched the exploit, and offered two years of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_f7fd0d0d98414d29Maine State AGfiled 2023-08-17(8d gap)Verified by operator
- bd_e71a88311b2e2220New Hampshire State AGfiled 2023-07-25(15d gap)Verified
- bd_904ab57c2f95240fVermont State AGfiled 2023-07-07(33d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571545
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2023
- Raw hash
- 5fab4c8084295c6f2fdaa6ae5a774c168c36b4fd80024453434f7cc99e039e17
Reporting entity
- Name
- M. Arthur Gensler Jr. & Associates, Inc.norm: m arthur gensler jr associates
Victim entity
- Name
- M. Arthur Gensler Jr. & Associates, Inc.norm: m arthur gensler jr associates
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 8, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.