HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICHEALTH_BASICPHILowContained
INDEPENDENT LIVING SYSTEMS, LLC.
bd_4457777d8bbc94fe · schema v1 · pii pii-v1
Full breach record for INDEPENDENT LIVING SYSTEMS, LLC. →Independent Living Systems, LLC notified consumers of a data security incident involving the MOVEit Transfer tool by Progress Software. The incident, stemming from a vulnerability reported on May 31, 2023, potentially exposed personal health information (PHI) and personal data including names, addresses, dates of birth, and health insurance details. ILS engaged forensic experts and law enforcement, disabled the tool, and offered two years of credit monitoring.
Vermont clock✗ VT AG >45 bday27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6dfd5bc658e9797dMontana State AGfiled 2023-12-08Candidate
- bd_fa7fed195d36b02cVermont State AGfiled 2023-12-08Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-08-upmc-health-plan-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2023
- Raw hash
- b05ebdc228dd850453cebfeaaf3c26eea66e55707f9b25fc40ce6dc0cbb638c6
Reporting entity
- Name
- INDEPENDENT LIVING SYSTEMS, LLC.norm: independent living
- Domain
- ilshealth.com
Victim entity
- Name
- INDEPENDENT LIVING SYSTEMS, LLC.norm: independent living
- Domain
- ilshealth.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Dec 8, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Third party
- via Progress Software
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 weeks(191 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.