HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedTargetedIDENTITY_BASICLowContained
University of Rochester
bd_419f463a975f38c7 · schema v1 · pii pii-v1
Full breach record for University of Rochester →University of Rochester notified Vermont AG of a data breach involving its MOVEit File Transfer vendor, Progress Software. An unauthorized third party exploited a vulnerability on May 27, 2023, to access personal information. Files containing personal info were potentially removed on July 19, 2023. The university engaged investigators and offered 24 months of credit monitoring.
Vermont clock✓ VT AG ≤14 bday9 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_7d744ab9ef9b3c31Leak Sitecl0pfiled 2023-07-14(13d gap)Verified
Regulatory filings (3) · sorted by filing gap
- bd_659d73894032e3aeMaine State AGfiled 2023-07-28Verified
- bd_8283f86271ea7a05Montana State AGfiled 2023-07-28Verified by operator
- bd_f7935ffb9c85c7d1California State AGfiled 2023-07-28Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-28-university-rochester-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- 1fe5d1876ec0c5a391ab73d5e04c1c48af587a7671906ec7282468bacf8b2390
Reporting entity
- Name
- University of Rochesternorm: university of rochester
- Domain
- rochester.edu
Victim entity
- Name
- University of Rochesternorm: university of rochester
- Domain
- rochester.edu
Incident
- Discovered
- Jul 19, 2023
- Materiality determined
- —
- Notification sent
- Jul 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.