DisclosureLens
HackingProfessional ServicesTechnologyProfessional ServicesVulnerability ExploitData ExfiltratedTargetedIdentity (basic)Government IDMediumContained

CBIZ, INC.

bd_79465978a9228cee · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Sep 1, 2023

To disclose

13 weeks

Affected

149state residents only

Linked

4 filings

Confidence

65%
Full breach record for CBIZ, INC.7 incidents on file

CBIZ, Inc. notified individuals of a data incident involving MOVEit Transfer software. An unauthorized party exploited a vulnerability in MOVEit to access a server and download data between May 29 and June 5, 2023. Affected data included names, dates of birth, and Social Security numbers. CBIZ patched the vulnerability and offered two years of identity monitoring.

Incident timeline

undetected · 2 days
discovery → filing · 13 weeks / 93 days

May 29, 2023

Begins

May 31, 2023

Discovered

Sep 1, 2023

Filed

vs. sector median

4 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGSep 1 · first
Montana State AGSep 1 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.