HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Maximus
bd_624423274a86bca1 · schema v1 · pii pii-v1
Full breach record for Maximus →Maximus Health Services, Inc. notified individuals of a security incident involving the MOVEit Transfer software vulnerability. Unauthorized access occurred between May 27 and May 31, 2023, resulting in the exfiltration of personal information. Maximus took the environment offline, applied vendor patches, and is offering two years of credit monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_72e613c2b523f548Montana State AGfiled 2023-07-28(28d gap)Candidate
- bd_eab9649547b60fb2Idaho State AGfiled 2023-07-28(28d gap)Candidate
- bd_3bd082ea9757a6faSEC 8-Kfiled 2023-07-26(30d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/Maximus-Sample-Individual-Notice-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2023
- Raw hash
- 6bbc3314e0bce5e8d4a139879987a691fbcf1fd66f76c593f1c9b64e0c9f0ae0
Reporting entity
- Name
- Maximusnorm: maximus
- Domain
- maximus.com
Victim entity
- Name
- Maximusnorm: maximus
- Domain
- maximus.com
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified the Department of the incidentcooperating with law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.