FEDERALItem 8.01 · voluntaryHackingVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedEmployee Data InvolvedN-DayPIIIDENTITY_BASICEMPLOYMENTLowActive
Paycom Software, Inc.
bd_3cdcc1009c5cce36 · schema v1 · pii pii-v1
Full breach record for Paycom Software, Inc. →Paycom Software, Inc. disclosed a cybersecurity incident resulting from a vulnerability in Progress Software's MOVEit file transfer software. An unauthorized third party downloaded files from Paycom's MOVEit server, accessing PII of approximately 127 former and current clients and certain employee records. Paycom patched the software, engaged forensic experts, and is contacting affected clients.
SEC clockMateriality determined Jul 20, 2023 → Filed Jul 20, 20230d ✓ SEC 4-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed127 affectedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1590955/000119312523190562/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 20, 2023
- Raw hash
- 273ebdc4a523270dc0e239c774f4af3a0eb3acbe985f8f12fcf488f2eab2ddce
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Paycom Software, Inc.norm: paycom software
- SEC CIK
- 0001590955
Victim entity
- Name
- Paycom Software, Inc.norm: paycom software
- SEC CIK
- 0001590955
Incident
- Discovered
- May 31, 2023
- Materiality determined
- Jul 20, 2023
- Notification sent
- —
- Affected individuals
- 127
- Data types
- PIIIDENTITY_BASICEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 ChannelT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jul 20, 2023→ Filed: Jul 20, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.