Nuance Communications, Inc
bd_42ba23005cabceb8 · schema v1 · pii pii-v1
Full breach record for Nuance Communications, Inc →Nuance Communications, Inc. notified the New Hampshire Attorney General of a security incident involving a zero-day vulnerability in Progress Software's MOVEit Transfer application. The attack occurred on May 28-29, 2023, and was discovered by Nuance on May 31, 2023. The breach impacted approximately 1,259 New Hampshire residents, exposing medical and healthcare information. Nuance took immediate response actions, including securing servers, engaging Microsoft and legal counsel, and notifying the FBI. Remediation included offering credit monitoring services to affected individuals.
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2d18f75acad25ac9Maine State AGfiled 2023-09-15Candidate
- bd_829cc01dc8d0b732California State AGfiled 2023-09-15Verified
- bd_f82949cd77b8e1acMontana State AGfiled 2023-09-15Verified
- bd_119ca48980839f9bDelaware State AGfiled 2023-09-18(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 4d gap
- bd_b80d8c8f8a2bace4Delaware State AGfiled 2023-09-18(3d gap)Verified
- bd_61e841c1c6509034Oregon State AGfiled 2023-09-19(4d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nuance-communications-20230915.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2023
- Raw hash
- e84f726a2c59935366ef51ffaccc163b510fa33cb7a84926ac4345cb8188a334
Reporting entity
- Name
- Nuance Communications, Incnorm: nuance communications
Victim entity
- Name
- Nuance Communications, Incnorm: nuance communications
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Sep 15, 2023
- Affected individuals
- 1,259
- Data types
- PIIPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the U.S. Department of Health and Human Services, Office for Civil Rights (OCR)Notified applicable state regulators, including certain Attorneys General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(107 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.