HackingVulnerability ExploitCl0pSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Riverside County Office of Education
bd_3ad836cc9d79e7d0 · schema v1 · pii pii-v1
Full breach record for Riverside County Office of Education →Riverside County Office of Education reported a data breach affecting its MOVEit Transfer file transfer appliance. The incident occurred on May 27, 2023, due to a vulnerability in the Progress Software MOVEit product (supply chain compromise). The breach potentially exposed personal information including names, addresses, and possibly Social Security numbers of students, parents, and employees. The organization is notifying affected individuals as required by California law.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576190
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 7, 2023
- Raw hash
- 706e8233c2e62ae22844c6c9006c55b3851af288443fe6eab1224835ebda3a74
Reporting entity
- Name
- Riverside County Office of Educationnorm: riverside county office of education
- Domain
- rcoe.us
Victim entity
- Name
- Riverside County Office of Educationnorm: riverside county office of education
- Domain
- rcoe.us
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Cl0pExternalFinancial
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.