HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
M. Arthur Gensler Jr. & Associates, Inc.
bd_904ab57c2f95240f · schema v1 · pii pii-v1
Full breach record for M. Arthur Gensler Jr. & Associates, Inc. →M. Arthur Gensler, Jr. & Associates disclosed a data breach involving the third-party file transfer vendor Progress MOVEit. Between May 27-31, 2023, an unauthorized party accessed and copied files containing names, SSNs, dates of birth, and home addresses of US colleagues. Gensler patched the exploit, secured systems, and offered two years of Experian credit monitoring.
Vermont clock⏱ VT AG >14 bday29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_e71a88311b2e2220New Hampshire State AGfiled 2023-07-25(18d gap)Verified
- bd_2d48359ec9022072California State AGfiled 2023-08-09(33d gap)Candidate
- bd_f7fd0d0d98414d29Maine State AGfiled 2023-08-17(41d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-07-m-arthur-gensler-jr-associates-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2023
- Raw hash
- 7e0cdc0d314b8bf1d72f9c7e577df0d8eb428ba3b3348137d39e6cb0f63f7fd9
Reporting entity
- Name
- M. Arthur Gensler Jr. & Associates, Inc.norm: m arthur gensler jr associates
Victim entity
- Name
- M. Arthur Gensler Jr. & Associates, Inc.norm: m arthur gensler jr associates
Incident
- Discovered
- Jun 8, 2023
- Materiality determined
- —
- Notification sent
- Jul 7, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.