HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Sovos Compliance, LLC
bd_6622b41cafd1ef5d · schema v1 · pii pii-v1
Full breach record for Sovos Compliance, LLC →Sovos Compliance, LLC reported that unauthorized actors exploited a previously unknown vulnerability (zero-day) in Progress Software's MOVEit Transfer application on May 30, 2023, to download personal information. Sovos detected the incident on May 31, 2023, took the application offline, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of identity monitoring.
This filing is one of 21 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_084e33a4c378d534Vermont State AGfiled 2023-08-23(42d gap)Verified
- bd_1263c3b040734745Delaware State AGfiled 2023-08-23(42d gap)Verified
- bd_186dbb4a134b0369New Hampshire State AGfiled 2023-08-23(42d gap)Verified
- bd_1d16661cc5f0c5c2Maine State AGfiled 2023-09-05(55d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 72d gap
- bd_2644df19a41ec830California State AGfiled 2023-09-22(72d gap)Verified
- bd_40393771a63e8372Oregon State AGfiled 2023-09-22(72d gap)Verified
- bd_7d54e64352e44cf5Vermont State AGfiled 2023-09-22(72d gap)Verified
- bd_9c65f917da81d4d8Maine State AGfiled 2023-09-22(72d gap)Verified
- bd_bfa8650066e49884Washington State AGfiled 2023-09-22(72d gap)Verified
- bd_fd9a9a297311db80New Hampshire State AGfiled 2023-09-22(72d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sovos-compliance-20230712.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 12, 2023
- Raw hash
- f3662d9c3164b7306ca179a136a9e9b99468e18ab4b3f115e42ca84a50b0e3c8
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.