HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
City Facilities Management (US) LLC
bd_30e3ff28eaf35b92 · schema v1 · pii pii-v1
Full breach record for City Facilities Management (US) LLC →City Facilities Management (US) LLC notified Vermont AG that a third-party vendor, Paycor, was impacted by the MOVEit Transfer vulnerability (Progress Software). The incident exposed affected individuals' addresses and Social Security numbers. City coordinated with Paycor, implemented recommended actions, and provided 24 months of credit monitoring. No specific count of affected individuals was disclosed in the filing.
Vermont clock⏱ VT AG >14 bday28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e9332d3a0ac43497Maine State AGfiled 2023-12-28Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-28-city-facilities-management-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 28, 2023
- Raw hash
- 4b8946f5c5deb43f59461aff445cba9b1117d4edc452261a8e5a3bb045931482
Reporting entity
- Name
- City Facilities Management (US) LLCnorm: city facilities management us
Victim entity
- Name
- City Facilities Management (US) LLCnorm: city facilities management us
Incident
- Discovered
- Nov 30, 2023
- Materiality determined
- —
- Notification sent
- Dec 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.