HackingVulnerability ExploitData ExfiltratedData EncryptedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Data Media Associates
bd_b6d2939432620ba9 · schema v1 · pii pii-v1
Full breach record for Data Media Associates →Data Media Associates, LLC (DMA) notified Delaware residents of a data security incident involving its MOVEit Transfer software. In June 2023, DMA discovered a critical vulnerability in the managed file transfer solution and patched the system. An investigation revealed that unauthorized actors acquired certain data, potentially including protected health information (PHI), names, and government IDs. DMA engaged external experts, patched the system, and is evaluating additional safeguards. The incident affected approximately 2,500 organizations worldwide.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_44951a0ed5c0c1c7California State AGfiled 2023-08-23Verified
- bd_f47ab4ae0c5fc070Maine State AGfiled 2023-08-23Verified
- bd_5fe69a1c32fcae1bWashington State AGfiled 2023-09-25(33d gap)Verified
- bd_dd8d071e11b9229bMaine State AGfiled 2023-09-25(33d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 47d gap
- bd_54c0ed94f9613269HHS OCRfiled 2023-10-09(47d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/DMA-Notification-Letter_DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2023
- Raw hash
- c07c2c05a26de0fa90ad73f11a24f714af17f52ef10c1d43d00e75c2c3f76b29
Reporting entity
- Name
- Data Media Associatesnorm: data media associates
Victim entity
- Name
- Data Media Associatesnorm: data media associates
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Aug 23, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.