HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICHEALTH_BASICEMPLOYMENTLowContained
Oak Ridge Associated Universities, Incorporated
bd_393e41f072f2bf09 · schema v1 · pii pii-v1
Full breach record for Oak Ridge Associated Universities, Incorporated →Oak Ridge Associated Universities (ORAU) notified California residents of a data breach involving the MOVEit Transfer software. A vulnerability in Progress Software's MOVEit platform allowed an unauthorized party to access and download data between May 28 and May 30, 2023. ORAU discovered the incident on May 31, 2023. Affected individuals include former DOE employees, contractors, and subcontractors. Data exposed includes names and potentially other personal information. ORAU offered 24 months of credit monitoring and identity theft protection services.
California clockDiscovered May 31, 2023 → Notified Aug 21, 202382d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_964719921d9afe4fLeak Sitecl0pfiled 2023-07-26(26d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_1be1194ec5574864Oregon State AGfiled 2023-08-21Verified
- bd_886bd4fa64f2a2baMontana State AGfiled 2023-08-21Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572171
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 21, 2023
- Raw hash
- c21b08e17d274df543c76116f58cc6283570baacb3400dd5103524f1b5a58d27
Reporting entity
- Name
- Oak Ridge Associated Universities, Incorporatednorm: oak ridge associated universities
- Domain
- orau.org
Victim entity
- Name
- Oak Ridge Associated Universities, Incorporatednorm: oak ridge associated universities
- Domain
- orau.org
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 21, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASICEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified California Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(82 days from discovery to filing)
- Compliance flags
- CA 60-day late · 82dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Aug 21, 202382d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.