HackingVulnerability ExploitData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryTargetedIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICCVE-2023-35164CriticalContained
Medical Eye Services, Inc.
bd_57de58eb876f18d7 · schema v1 · pii pii-v1
Full breach record for Medical Eye Services, Inc. →Medical Eye Services, Inc. (MESVision) experienced a data breach involving its MOVEit Transfer server due to a critical vulnerability (CVE-2023-35164). The incident occurred between May 28 and May 31, 2023, and was discovered on August 23, 2023. Approximately 346,828 individuals were affected, with data including names, Social Security numbers, and protected health information exfiltrated. The company engaged forensic investigators, notified law enforcement, and provided credit monitoring to affected individuals.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_6beb8ba0bda9123fCalifornia State AGfiled 2023-11-17(5d gap)Verified
- bd_8695a245d6b38536Maine State AGfiled 2023-11-17(5d gap)Verified
- bd_b9bc0c3a55fd236eOregon State AGfiled 2023-11-17(5d gap)Verified
- bd_c0b9305f53e1673eMaine State AGfiled 2023-11-15(7d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 70d gap
- bd_8fd3b5758701dc53California State AGfiled 2023-11-14(8d gap)Verified
- bd_97132facec254d63Montana State AGfiled 2023-11-14(8d gap)Candidate
- bd_bac779c9da975873Oregon State AGfiled 2023-11-14(8d gap)Verified
- bd_e353aefdc5628e28California State AGfiled 2024-01-30(69d gap)Verified
- bd_98132492ce988ce0Maine State AGfiled 2024-01-31(70d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/medical-eye-services-20231122.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- 3ff9d22f6e983edeb16b5362cca0bf76f4ef945156e248691e1a803cdd3496ef
Reporting entity
- Name
- Medical Eye Services, Inc.norm: medical eye
- Domain
- medeye.net
Victim entity
- Name
- Medical Eye Services, Inc.norm: medical eye
- Domain
- medeye.net
Incident
- Discovered
- Aug 23, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 346,828
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Department of Justice
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.