HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
ERNST & YOUNG LLP
bd_623abffde3aa6f64 · schema v1 · pii pii-v1
Full breach record for ERNST & YOUNG LLP →Ernst & Young LLP notified customers of a data breach involving personal data handled for Bank of America. On May 31, 2023, EY was informed by third-party supplier Progress Software Corporation of a security vulnerability in the MOVEit Transfer solution. The breach window is May 27-31, 2023. Affected data may include names, addresses, financial account information, credit/debit card numbers, and SSNs. EY engaged third-party security experts and is offering two years of identity theft protection via Experian.
California clockDiscovered May 31, 2023 → Notified Aug 9, 202370d ✗ CA 60-day late13 months discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-587852
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2024
- Raw hash
- 3dafaa10d6f8382392b86dd0ffdd7d9013eff12455f87d4bff53ca56127341b7
Reporting entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Victim entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 9, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Progress Software Corporation
- Initial access
- supply_chain
Compliance
- Time to disclose
- 13 months(397 days from discovery to filing)
- Compliance flags
- CA 60-day late · 70d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Aug 9, 202370d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.