HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIDENTITY_BASICLowContained
The Johns Hopkins Health System Corporation
bd_aa5b4ac8f7c63a37 · schema v1 · pii pii-v1
Full breach record for The Johns Hopkins Health System Corporation →Johns Hopkins University Health System Corporation notified the NH AG of a MOVEit file transfer vulnerability exploited on May 29, 2023. Unauthorized access led to document downloads affecting 47 NH residents. Notification letters were mailed June 23, 2023, offering credit monitoring. The vendor Progress Software disclosed the zero-day vulnerability on May 31, 2023.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b47ce74078dd95e6HHS OCRfiled 2023-07-31(10d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/johns-hopkins-university-health-system-corporation-20230721.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2023
- Raw hash
- 165f1385279b1355cd4e472f5745f9876062133d58aabb917545c308b3c251fc
Reporting entity
- Name
- The Johns Hopkins Health System Corporationnorm: the johns hopkins health system
Victim entity
- Name
- The Johns Hopkins Health System Corporationnorm: the johns hopkins health system
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Jun 23, 2023
- Affected individuals
- 47
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.