HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Johns Hopkins University and The Johns Hopkins Health System Corporation
bd_6e8361a25d311431 · schema v1 · pii pii-v1
Full breach record for The Johns Hopkins University and The Johns Hopkins Health System Corporation →The Johns Hopkins University and Health System notified individuals of a data breach involving the MOVEit file-transfer software. An unauthorized party accessed a server on May 29, 2023, downloading personal information including names, SSNs, and dates of birth. JHU engaged forensic investigators, disconnected the server, and provided two years of credit monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday23 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8ddec3a29b43d16aMontana State AGfiled 2023-07-21(28d gap)Candidate
- bd_aaab7b2385df4fc1California State AGfiled 2023-07-25(32d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-23-johns-hopkins-university-and-johns-hopkins-hopkins-health-system-corporation-data-breach
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 23, 2023
- Raw hash
- 906d22166d16cb94138e77c9882b8963d24069e777083e104c775c572aba083a
Reporting entity
- Name
- The Johns Hopkins University and The Johns Hopkins Health System Corporationnorm: the johns hopkins university and the johns hopkins health system
Victim entity
- Name
- The Johns Hopkins University and The Johns Hopkins Health System Corporationnorm: the johns hopkins university and the johns hopkins health system
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Jul 11, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.