DisclosureLens
HackingEducationGovernmentEducationVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPIIIdentity (basic)Government IDMediumContained

Riverside County Office of Education

bd_3ad836cc9d79e7d0 · schema v1 · pii pii-v1

Severity

Medium

Discovered

—

Filed

Nov 7, 2023

To disclose

—

Affected

Not disclosed

Confidence

66%
Full breach record for Riverside County Office of Education →3 incidents on file

Riverside County Office of Education reported a data breach affecting its MOVEit Transfer file transfer appliance. The incident occurred on May 27, 2023, due to a vulnerability in the Progress Software MOVEit product (supply chain compromise). The breach potentially exposed personal information including names, addresses, and possibly Social Security numbers of students, parents, and employees. The organization is notifying affected individuals as required by California law.

Incident timeline

May 27, 2023

Begins

Nov 7, 2023

Filed

Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.