HackingVulnerability ExploitCapture Stored DataCL0P Ransomware GangData ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_BASICLowContained
Ciena
bd_8facdae0482870ce · schema v1 · pii pii-v1
Full breach record for Ciena →Ciena Corporation reported a security incident involving the MOVEit Transfer application by Progress Software. An unauthorized party exploited a critical vulnerability to access files on May 28-29, 2023. The breach affected the personal information of one New Hampshire resident. Ciena detected the activity on May 30, 2023, patched the vulnerability, notified law enforcement, and offered two years of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ciena-corporation-20230905.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2023
- Raw hash
- 42b827c963c0ba61fcff0a5e2c645cac871e99d64d4adf9a90f50716758187ac
Reporting entity
- Name
- Cienanorm: ciena
Victim entity
- Name
- Cienanorm: ciena
Incident
- Discovered
- May 30, 2023
- Materiality determined
- Jul 24, 2023
- Notification sent
- Sep 8, 2023
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access· CL0P Ransomware Gang
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0P Ransomware GangExternalFinancial
- Regulator citations
- Notified New Hampshire Department of JusticeNotified relevant data protection authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.