ERNST & YOUNG LLP
bd_342a8e17707d445d · schema v1 · pii pii-v1
Full breach record for ERNST & YOUNG LLP →5 incidents on fileErnst & Young LLP notified the California Attorney General of a data breach involving personal data of Bank of America customers. On May 31, 2023, EY was informed by third-party supplier Progress Software Corporation of a security vulnerability in the MOVEit Transfer solution. The breach window is May 27-31, 2023. Affected data may include names, addresses, financial account information, credit/debit card numbers, and Social Security numbers. EY engaged third-party security experts and is offering two years of complimentary identity theft protection via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
May 27, 2023
Begins
May 31, 2023
Discovered
Aug 9, 2023
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Delaware State AGbd_51121ff37fe0619a2023-08-09Verified
- Massachusetts State AGbd_6468994aed51a5192023-08-09Verified by operator
- Maine State AGbd_8403dcd75972f36e2023-08-09Verified
- Indiana State AGbd_941fd2c5aa2026e22023-08-09Verified by operator
Show 6 more filings ↓Show fewer ↑up to 265d gap
- Montana State AGbd_962a060b07cd01d62023-08-09Verified
- Oregon State AGbd_43034954cfbe06cc2023-08-22 · +13dVerified
- Indiana State AGbd_74745e5983f6eb6e2023-08-24 · +15dVerified by operator
- South Carolina State AGbd_1a497359484fd3612023-08-28 · +19dVerified by operator
- Massachusetts State AGbd_acdd5c6a642710682023-08-29 · +20dVerified by operator
- New Hampshire State AGbd_d769d3dcc09c3cbc2024-04-30 · +265dVerified
Showing first 10 of 14 linked disclosures.
Filing propagation · 11 filings · 9 states
View merged incident ↗Pattern: first filing Aug 9 (DE), last Apr 30 (NH) — a 265-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 14 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.