DisclosureLens
HackingProfessional ServicesProfessional ServicesVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDMediumContained

Sovos Compliance, LLC

bd_a489ee137aa91b8d · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Jul 13, 2023

To disclose

6 weeks

Affected

Not disclosed

Linked

22 filings

Confidence

64%
Full breach record for Sovos Compliance, LLC4 incidents on file

Sovos Compliance, LLC notified the California AG of a security event where unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application. The breach occurred between May 27 and May 30, 2023, and was discovered on May 31, 2023. Personal information, including names and potentially Social Security numbers, was exfiltrated. Sovos took the application offline, engaged forensic experts, notified law enforcement, and offered two years of identity monitoring to affected individuals.

Incident timeline

undetected · 4 days
discovery → filing · 6 weeks / 43 days

May 27, 2023

Begins

May 31, 2023

Discovered

Jul 13, 2023

Filed

vs. sector median

12 wks faster

This filing is one of 22 about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 71d gap

Showing first 10 of 21 linked disclosures.

Filing propagation · 11 filings · 7 states

View merged incident ↗

Pattern: first filing Jul 13 (CA), last Sep 22 (NH) — a 71-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Cascade drawn from the first 10 linked disclosures of 21 — the full spread may be wider.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.