DisclosureLens
HackingGovernmentGovernmentVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Identity (basic)Government IDPIIHighContained

State of Maine

bd_a883a45dffbdc16c · schema v1 · pii pii-v1

Severity

High

Discovered

May 31, 2023

Filed

May 9, 2024

To disclose

49 weeks

Affected

10,848state residents only

Confidence

66%
Full breach record for State of Maine3 incidents on file

Supplemental notice on behalf of the State of Maine regarding the MOVEit data security incident. The vulnerability was exploited between May 28-29, 2023. The State discovered the incident on May 31, 2023. Initial notifications began November 9, 2023. A revised count identifies 10,848 New Hampshire residents affected. Data types include PII and government IDs. Credit monitoring was offered.

Incident timeline

undetected · 3 days
discovery → filing · 49 weeks / 344 days

May 28, 2023

Begins

May 31, 2023

Discovered

May 9, 2024

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed10,848 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.