HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedZero-DayCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
BALTIMORE COUNTY EMPLOYEES
bd_79add972b8719b06 · schema v1 · pii pii-v1
Full breach record for BALTIMORE COUNTY EMPLOYEES →Baltimore County, Maryland reported a data breach affecting 14,846 individuals due to a third-party vendor incident. The vendor, Pension Benefit Information ("PBI"), was compromised via the MOVEit Transfer software vulnerability. The breach occurred between May 29 and May 30, 2023, and was discovered on June 16, 2023. Affected information includes names and Social Security Numbers. PBI began notifying individuals on August 10, 2023, and offered credit monitoring services.
Maine clockDiscovered Jun 16, 2023 → Filed with AG Aug 16, 202361d ⏱ ME AG >30d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5d6ade8125836f65Montana State AGfiled 2023-08-15(1d gap)Candidate
- bd_5a1bc227829bfc3dNew Hampshire State AGfiled 2023-08-14(2d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/e95c82b1-804f-46c0-aedf-4eaabbfefb62.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 16, 2023
- Raw hash
- 3a1e13c3e0fcfacb498cd894a6969be1d66ed4b85b78ee745eec9a7a0d342323
Reporting entity
- Name
- BALTIMORE COUNTY EMPLOYEESnorm: baltimore county employees
Victim entity
- Name
- BALTIMORE COUNTY EMPLOYEESnorm: baltimore county employees
Incident
- Discovered
- Jun 16, 2023
- Materiality determined
- —
- Notification sent
- Aug 10, 2023
- Affected individuals
- 14,846
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- ME AG >30d · 61d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 16, 2023→ Filed with AG: Aug 16, 202361d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.