HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
ERNST & YOUNG LLP
bd_342a8e17707d445d · schema v1 · pii pii-v1
Full breach record for ERNST & YOUNG LLP →Ernst & Young LLP notified the California Attorney General of a data breach involving personal data of Bank of America customers. On May 31, 2023, EY was informed by third-party supplier Progress Software Corporation of a security vulnerability in the MOVEit Transfer solution. The breach window is May 27-31, 2023. Affected data may include names, addresses, financial account information, credit/debit card numbers, and Social Security numbers. EY engaged third-party security experts and is offering two years of complimentary identity theft protection via Experian.
California clockDiscovered May 31, 2023 → Notified Aug 9, 202370d ✗ CA 60-day late10 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_51121ff37fe0619aDelaware State AGfiled 2023-08-09Verified
- bd_8403dcd75972f36eMaine State AGfiled 2023-08-09Verified
- bd_9f0a166a0e807419New Hampshire State AGfiled 2023-08-09Verified
- bd_f2b7e0ce70ee52a5Washington State AGfiled 2023-08-09Verified
Show 1 more filing ↓Show fewer ↑up to 13d gap
- bd_43034954cfbe06ccOregon State AGfiled 2023-08-22(13d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571532
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2023
- Raw hash
- aa61117db256d441b66d12259894a06207ede3c52ab979e3f058b967e9f230da
Reporting entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Victim entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 9, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Progress Software Corporation
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- CA 60-day late · 70d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Aug 9, 202370d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.