HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICLowContained
CBIZ, INC.
bd_ab8685161ea5f6d1 · schema v1 · pii pii-v1
Full breach record for CBIZ, INC. →CBIZ, Inc. notified the New Hampshire Attorney General on September 1, 2023, regarding a MOVEit Transfer vulnerability exploited between May 29 and June 5, 2023. The incident affected 77 New Hampshire residents. CBIZ applied patches, investigated, and mailed notifications offering credit monitoring. Data exfiltrated included personal information.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_79465978a9228ceeMontana State AGfiled 2023-09-01Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cbiz-20230901.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2023
- Raw hash
- 74de955e42cd5ea18b1fb05cbf632d1732dd52325bf646640689613719ce7b0c
Reporting entity
- Name
- CBIZ, INC.norm: cbiz
- Domain
- cbiz.com
Victim entity
- Name
- CBIZ, INC.norm: cbiz
- Domain
- cbiz.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Sep 1, 2023
- Affected individuals
- 77
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.