HackingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
ERNST & YOUNG LLP
bd_8403dcd75972f36e · schema v1 · pii pii-v1
Full breach record for ERNST & YOUNG LLP →Ernst & Young LLP reported an external system breach (hacking) occurring between May 27 and May 31, 2023, discovered on May 31, 2023. The incident affected 30,210 individuals, including 100 Maine residents. Acquired data included names and driver's license numbers. Notification was sent electronically on August 9, 2023, and two years of identity theft protection services were provided by Experian.
Maine clockDiscovered May 31, 2023 → Filed with AG Aug 9, 202370d ⏱ ME AG >30d10 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_342a8e17707d445dCalifornia State AGfiled 2023-08-09Candidate
- bd_51121ff37fe0619aDelaware State AGfiled 2023-08-09Verified
- bd_9f0a166a0e807419New Hampshire State AGfiled 2023-08-09Verified
- bd_f2b7e0ce70ee52a5Washington State AGfiled 2023-08-09Verified
Show 1 more filing ↓Show fewer ↑up to 13d gap
- bd_43034954cfbe06ccOregon State AGfiled 2023-08-22(13d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c43aee1c-dbc4-4a6d-b0d1-147ad3b23c37.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2023
- Raw hash
- fda468223d2b5947eeaf6342310f097f8f26a49d556194f6297c314518e9cfac
Reporting entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Victim entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 9, 2023
- Affected individuals
- 30,210
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- ME AG >30d · 70dME resident >60d · 70d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 31, 2023→ Filed with AG: Aug 9, 202370d 30 days (soft) ME AG >30d Maine Discovered: May 31, 2023→ Notified: Aug 9, 202370d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.