HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCVE-2023-34362CriticalContained
Arch Capital Services LLC
bd_3123a62f59c7451e · schema v1 · pii pii-v1
Full breach record for Arch Capital Services LLC →Arch Capital Services notified consumers of a data breach stemming from the MOVEit transfer software vulnerability (CVE-2023-34362) exploited by the Cl0p threat actor. The incident, discovered May 26, 2023, resulted in the exfiltration of personal information including names, SSNs, and financial account details for approximately 100,000 individuals. Arch Capital Services offered one year of credit monitoring.
Vermont clock✗ VT AG >45 bday35 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a73e419a4c0a813fIndiana State AGfiled 2024-01-25Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-01-25-arch-capital-services-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 25, 2024
- Raw hash
- 79070ca89d2dbf3ff1cb77d8169d70030da192fced96f12641f501872263df0b
Reporting entity
- Name
- Arch Capital Services LLCnorm: arch
Victim entity
- Name
- Arch Capital Services LLCnorm: arch
Incident
- Discovered
- May 26, 2023
- Materiality determined
- Jan 25, 2024
- Notification sent
- Jan 25, 2024
- Affected individuals
- 100,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- supply_chain
- CVE references
Compliance
- Time to disclose
- 35 weeks(244 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.