HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Sovos Compliance, LLC
bd_a1917778d028ed83 · schema v1 · pii pii-v1
Full breach record for Sovos Compliance, LLC →Sovos Compliance, LLC disclosed a security event involving the MOVEit Transfer application vulnerability discovered on May 31, 2023. Unauthorized actors exploited the vulnerability to download personal information of individuals associated with unclaimed property claims. Sovos took the application offline, retained cybersecurity experts, notified law enforcement, and is offering two years of complimentary credit monitoring and identity restoration services through Kroll.
This filing is one of 21 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_084e33a4c378d534Vermont State AGfiled 2023-08-23(42d gap)Verified
- bd_1263c3b040734745Delaware State AGfiled 2023-08-23(42d gap)Verified
- bd_186dbb4a134b0369New Hampshire State AGfiled 2023-08-23(42d gap)Verified
- bd_1d16661cc5f0c5c2Maine State AGfiled 2023-09-05(55d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 72d gap
- bd_2644df19a41ec830California State AGfiled 2023-09-22(72d gap)Verified
- bd_40393771a63e8372Oregon State AGfiled 2023-09-22(72d gap)Verified
- bd_7d54e64352e44cf5Vermont State AGfiled 2023-09-22(72d gap)Verified
- bd_9c65f917da81d4d8Maine State AGfiled 2023-09-22(72d gap)Verified
- bd_bfa8650066e49884Washington State AGfiled 2023-09-22(72d gap)Verified
- bd_fd9a9a297311db80New Hampshire State AGfiled 2023-09-22(72d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/Delaware-Exhibit-A-and-B.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 12, 2023
- Raw hash
- 1e546a1900d02d7788e9ce425b04161f37722b7442845bc36bcb34863f9ec2a0
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.