HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
EMS Management and Consultants Inc.
bd_6035553c200b8f0a · schema v1 · pii pii-v1
Full breach record for EMS Management and Consultants Inc. →EMS Management and Consultants, Inc. reported a data breach affecting 31 New Hampshire residents. An unknown actor accessed the MOVEit Transfer server on May 30, 2023, exploiting a vulnerability disclosed by Progress Software Corp. in May/June 2023. Personal information, including names and government IDs, was exfiltrated. EMS|MC discovered the incident on July 12, 2023, after a data review. Notices were sent to affected individuals on August 9, 2023, offering credit monitoring. EMS| engaged forensic specialists and patched the vulnerable software.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_08185f81df2dd2f9HHS OCRfiled 2023-08-10Verified
- bd_87f59e0d4c0abceaMaine State AGfiled 2023-08-10Verified
- bd_8ff9e4e1ed3639a7Montana State AGfiled 2023-08-10Verified
- bd_f7bd2cf2bd973dbdVermont State AGfiled 2023-08-10Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ems-management-consultants-20230810.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 10, 2023
- Raw hash
- 489eaeb574392c2fdd1b6f2d0ed6d923b708f6067a5483b8c445c407e1f06503
Reporting entity
- Name
- EMS Management and Consultants Inc.norm: ems management and consultants
Victim entity
- Name
- EMS Management and Consultants Inc.norm: ems management and consultants
Incident
- Discovered
- Jul 12, 2023
- Materiality determined
- Jul 12, 2023
- Notification sent
- Aug 9, 2023
- Affected individuals
- 31
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the U.S. Department of Health and Human ServicesProvided written notice to relevant state and federal regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.