DisclosureLens
HackingProfessional ServicesProfessional ServicesVulnerability ExploitZero-DayData ExfiltratedIdentity (basic)Government IDHighContained

HUMANGOOD WASHINGTON

bd_a066b2bc2553ea59 · schema v1 · pii pii-v1

Severity

High

Discovered

Feb 4, 2023

Filed

May 16, 2023

To disclose

14 weeks

Affected

1,411state residents only

Confidence

69%
Full breach record for HUMANGOOD WASHINGTON

HumanGood experienced a data security incident involving its GoAnywhere file transfer tool. An unauthorized actor exploited a previously unknown vulnerability to access accounts between Jan 29-31, 2023. HumanGood was notified on Feb 4, 2023, and identified affected individuals by April 5, 2023. Incident involved team member census data including names, DOBs, phone numbers, and partial SSNs. 1,411 Washington residents were notified.

Washington clock WA AG >90d14 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 6 days
discovery → filing · 14 weeks / 101 days

Jan 29, 2023

Begins

Feb 4, 2023

Discovered

May 16, 2023

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,411 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.