ERNST & YOUNG LLP
bd_51121ff37fe0619a · schema v1 · pii pii-v1
Full breach record for ERNST & YOUNG LLP →Ernst & Young LLP (EY US) notified the Delaware Attorney General on August 30, 2023, of a security incident involving its third-party supplier, Progress Software. A vulnerability in Progress Software's MOVEit Transfer file transfer solution compromised files containing personal data of 2,408 Delaware residents. Data potentially exposed includes names, addresses, financial account information, credit/debit card numbers, Social Security numbers, and government-issued IDs. EY US began mailing notifications on August 9, 2023, and offered 24 months of credit monitoring via Experian. Bank of America, an EY client, was not impacted.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_342a8e17707d445dCalifornia State AGfiled 2023-08-09Candidate
- bd_8403dcd75972f36eMaine State AGfiled 2023-08-09Verified
- bd_9f0a166a0e807419New Hampshire State AGfiled 2023-08-09Verified
- bd_f2b7e0ce70ee52a5Washington State AGfiled 2023-08-09Verified
Show 1 more filing ↓Show fewer ↑up to 13d gap
- bd_43034954cfbe06ccOregon State AGfiled 2023-08-22(13d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/2023-08-30-EY-US-notice-to-DE-AG.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2023
- Raw hash
- bd595d2950f0327a6c7dba46f01ea4ccac2fd514ed9f073dc1c7d494b498f2e0
Reporting entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Victim entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 9, 2023
- Affected individuals
- 2,408
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified Delaware Attorney General
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.