HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
CareSource
bd_6c68eb604349c96d · schema v1 · pii pii-v1
Full breach record for CareSource →CareSource disclosed a data breach affecting its members due to a vulnerability in Progress Software's MOVEit transfer software. The incident, discovered on June 27, 2023, involved the exfiltration of protected health information (PHI) and personally identifiable information (PII), including SSNs and health conditions. CareSource patched the software and engaged Kroll to provide two years of credit monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 57 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_a5a734fce487738aCalifornia State AGfiled 2023-08-28(3d gap)Verified
- bd_8cae43083631f018Washington State AGfiled 2023-08-30(5d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-25-caresource-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2023
- Raw hash
- e637551c70a03fe7f561633648c0c050662f9c8b0f3cb22ced77a4c629ca164a
Reporting entity
- Name
- CareSourcenorm: caresource
- Domain
- caresource.com
Victim entity
- Name
- CareSourcenorm: caresource
- Domain
- caresource.com
Incident
- Discovered
- Jun 27, 2023
- Materiality determined
- —
- Notification sent
- Aug 25, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.