HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
The Johns Hopkins University and The Johns Hopkins Health System Corporation
bd_aaab7b2385df4fc1 · schema v1 · pii pii-v1
Full breach record for The Johns Hopkins University and The Johns Hopkins Health System Corporation →Johns Hopkins University and Health System experienced a data breach via a vulnerability in third-party MOVEit software. An unauthorized party accessed a server on May 29, 2023, and downloaded documents containing personal information. The incident was discovered on May 31, 2023. The organization disconnected the affected server, engaged forensic investigators, and is offering credit monitoring to affected individuals.
California clockDiscovered May 31, 2023 → Notified Jul 11, 202341d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8ddec3a29b43d16aMontana State AGfiled 2023-07-21(4d gap)Candidate
- bd_6e8361a25d311431Vermont State AGfiled 2023-06-23(32d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570847
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 25, 2023
- Raw hash
- 3b7884bdb105872afa7ea8e45c195fdb4d93ec3662cb3ce41397a87d483734c7
Reporting entity
- Name
- The Johns Hopkins University and The Johns Hopkins Health System Corporationnorm: the johns hopkins university and the johns hopkins health system
Victim entity
- Name
- The Johns Hopkins University and The Johns Hopkins Health System Corporationnorm: the johns hopkins university and the johns hopkins health system
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Jul 11, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 41d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Jul 11, 202341d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.