FEDERALItem 8.01 · voluntaryHackingGovernmentProfessional ServicesGovernmentVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsPIIPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICCVE-2023-34362CriticalActive
Maximus
bd_3bd082ea9757a6fa · schema v1 · pii pii-v1
Full breach record for Maximus →Maximus, Inc. disclosed via Form 8-K Item 8.01 that it was affected by the MOVEit zero-day vulnerability disclosed by Progress Software on May 31, 2023. An unauthorized third party accessed personal information — including Social Security numbers and protected health information — of at least 8 to 11 million individuals tied to government program data shared via MOVEit. Maximus estimates approximately $15 million in investigation and remediation costs for Q ending June 30, 2023. Investigation ongoing.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_72e613c2b523f548Montana State AGfiled 2023-07-28(2d gap)Candidate
- bd_eab9649547b60fb2Idaho State AGfiled 2023-07-28(2d gap)Candidate
- bd_624423274a86bca1Delaware State AGfiled 2023-08-25(30d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1032220/000103222023000061/mms-20230726.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 26, 2023
- Raw hash
- 81fda65c6acf1bbbb828f80824a7765a2240dee9ac15a284ea0bcb88bdb8b14e
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Maximusnorm: maximus
- SEC CIK
- 0001032220
- Domain
- maximus.com
Victim entity
- Name
- Maximusnorm: maximus
- SEC CIK
- 0001032220
- Domain
- maximus.com
- Industry
- GovernmentllmProfessional Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 11,000,000
- Data types
- PIIPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notifying federal and state regulatorsCooperating with law enforcement
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.