HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Curators of the University of Missouri
bd_441790aaefd4d414 · schema v1 · pii pii-v1
Full breach record for The Curators of the University of Missouri →University of Missouri notified Vermont AG of a data breach caused by exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer application. The incident, confirmed on September 7, 2023, resulted in the exfiltration of personal information including names and government IDs. The University engaged forensic experts, notified law enforcement, patched the vulnerability, and provided two years of identity monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_c3de8a40450c33a3Maine State AGfiled 2023-10-24(4d gap)Candidate
- bd_3a959c98420de3f4California State AGfiled 2023-10-25(5d gap)Verified
- bd_9e9feecb13b05e12New Hampshire State AGfiled 2023-10-25(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-20-university-missouri-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 20, 2023
- Raw hash
- 071f93986b5f2145606ca90df13027e4db2893a1bf50e78f93ac4a9a5a3ef340
Reporting entity
- Name
- The Curators of the University of Missourinorm: the curators of the university of missouri
Victim entity
- Name
- The Curators of the University of Missourinorm: the curators of the university of missouri
Incident
- Discovered
- Sep 7, 2023
- Materiality determined
- —
- Notification sent
- Oct 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.