HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
BRISTOL-MYERS SQUIBB COMPANY
bd_333dbf505a7fad0d · schema v1 · pii pii-v1
Full breach record for BRISTOL-MYERS SQUIBB COMPANY →Bristol Myers Squibb notified New Hampshire AG of a MOVEit vulnerability exploitation. Unauthorized access occurred as early as May 27, 2023. Data of 5 NH residents, including SSNs and names, was exfiltrated. BMS engaged law enforcement, patched the vulnerability, and offered 24 months of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_c7f73efea8f4322fWashington State AGfiled 2023-06-30(3d gap)Candidate
- bd_27d9a6315eb19d82Montana State AGfiled 2023-06-29(4d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bristol-myers-squibb-20230703.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2023
- Raw hash
- ab2c020f089bbcad54a73bab1d55e864656860b39a611fac668fe9a8e3caded3
Reporting entity
- Name
- BRISTOL-MYERS SQUIBB COMPANYnorm: bristol myers squibb
Victim entity
- Name
- BRISTOL-MYERS SQUIBB COMPANYnorm: bristol myers squibb
Incident
- Discovered
- May 31, 2023
- Materiality determined
- Jun 1, 2023
- Notification sent
- Jun 29, 2023
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Engaged U.S. law enforcementNotified data protection authorities, where applicable
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.