HackingVulnerability ExploitStolen CredentialsZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Fiduciary Outsourcing
bd_b867e887cbae7fb7 · schema v1 · pii pii-v1
Full breach record for Fiduciary Outsourcing →Fiduciary Outsourcing, LLC disclosed a data breach affecting client personal information due to a zero-day vulnerability in the MOVEit Transfer solution used by a third-party vendor. The vulnerability was reported on May 31, 2023. On March 1, 2024, the company discovered that certain files containing names were potentially removed from its network by unauthorized actors. The company engaged third-party professionals for investigation and is providing credit monitoring and fraud assistance to affected individuals. No broader network compromise occurred.
California clockDiscovered Mar 1, 2024 → Notified Mar 19, 202418d ✓ CA 60-day OK18 days discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1c16336e28435147Maine State AGfiled 2024-03-19Candidate
- bd_21222e64aab559c0Vermont State AGfiled 2024-03-19Verified
- bd_67d4bf413a4dd154Montana State AGfiled 2024-03-19Verified by operator
- bd_fd49051419592048Indiana State AGfiled 2024-03-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582685
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2024
- Raw hash
- c7d729219952596eb87462f0698a39f1609fdeb26abe0b3ab7415b08f9aa1e29
Reporting entity
- Name
- Fiduciary Outsourcingnorm: fiduciary outsourcing
Victim entity
- Name
- Fiduciary Outsourcingnorm: fiduciary outsourcing
Incident
- Discovered
- Mar 1, 2024
- Materiality determined
- —
- Notification sent
- Mar 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 18d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 1, 2024→ Notified: Mar 19, 202418d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.