State of Maine
bd_9f3c12779b714b64 · schema v1 · pii pii-v1
Full breach record for State of Maine →3 incidents on fileThe State of Maine experienced a data breach involving the MOVEit file transfer tool owned by Progress Software. Cybercriminals exploited a software vulnerability to access and download files from certain state agencies between May 28 and May 29, 2023. The State became aware of the incident on May 31, 2023. Affected data may include names and Social Security numbers or taxpayer identification numbers. The State blocked internet access to the server, patched the vulnerability, engaged legal and cybersecurity experts, and offered two years of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
May 31, 2023
Discovered
Nov 27, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Oregon State AGbd_d9f19ada2e1cd45a2023-11-27Verified
- HHS OCRbd_9fdd1746eaefe1732023-11-16 · +11dVerified
- New Hampshire State AGbd_0c414cef662e480b2023-11-15 · +12dVerified
- South Carolina State AGbd_068157c5ee80ff0a2023-11-14 · +13dVerified
Show 4 more filings ↓Show fewer ↑up to 18d gap
- Washington State AGbd_54ab15a9f1f46a492023-11-13 · +14dVerified
- Vermont State AGbd_3234f2a5a49275f02023-11-09 · +18dVerified
- Montana State AGbd_bb9048f3d846f18f2023-11-09 · +18dVerified
- Maine State AGbd_c6058d3ab49a2b3c2023-11-09 · +18dVerified
Filing propagation · 9 filings · 8 states
View merged incident ↗Pattern: first filing Nov 9 (VT), last Nov 27 (CA) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.