HackingSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
EY Law LLP
bd_44d5e4a55b7f6e1f · schema v1 · pii pii-v1
Full breach record for EY Law LLP →EY Law LLP notified the New Hampshire Attorney General of a data breach involving third-party supplier Progress Software's MOVEit Transfer solution. Unauthorized access occurred on or around May 31, 2023, affecting personal data of 20 New Hampshire residents. EY Law engaged forensic experts, secured systems, and began mailing notifications with credit monitoring services on August 3, 2023.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0414b97359611404Maine State AGfiled 2023-08-03Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ey-law-20230803.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 3, 2023
- Raw hash
- 48ed825c8c9c8eb63a17c01844189bf3c357844ee7c42d582133a0d74093de87
Reporting entity
- Name
- EY Law LLPnorm: ey law
Victim entity
- Name
- EY Law LLPnorm: ey law
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 3, 2023
- Affected individuals
- 20
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.