RCI, LLC
bd_b1f0369446f8ee14 · schema v1 · pii pii-v1
Full breach record for RCI, LLC →2 incidents on fileRCI, LLC notified the California AG of a data breach involving the MOVEit Transfer platform. The threat actor CLOP exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application to access and exfiltrate files between May 31 and June 1, 2023. Affected data included names, addresses, and government identification numbers (including SSNs). RCI engaged forensic investigators, patched the application, implemented additional access controls, and is providing one year of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Begins
May 31, 2023
Discovered
Mar 1, 2024
Filed
vs. sector median
+22 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_6bda4ba0f18ab55d2023-07-17 · +228dVerified by operator
Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGCLOPbd_0c2271b8e6a813702024-03-01Verified
- Massachusetts State AGbd_39f6f190b209c3de2024-03-01Verified
- Montana State AGCLOPbd_49c3ccfedb62aae62024-03-01Candidate
- Maine State AGbd_d04cbfaf4ecd86082024-03-01Verified
Show 2 more filings ↓Show fewer ↑up to 170d gap
- Vermont State AGCLOPbd_d7c523ed63f056b52024-03-01Verified
- Indiana State AGbd_a795a1402f57de072023-09-13 · +170dVerified by operator
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Sep 13 (IN), last Mar 1 (CA) — a 170-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.