State of Maine
bd_bb9048f3d846f18f · schema v1 · pii pii-v1
Full breach record for State of Maine →3 incidents on fileThe State of Maine disclosed a cybersecurity incident involving the MOVEit file transfer tool. A software vulnerability was exploited by cybercriminals between May 28-29, 2023, allowing unauthorized access and data download from Maine agencies. The State became aware of the vulnerability on May 31, 2023. Affected data included names and government identifiers (SSN/TIN). The State engaged legal counsel and cybersecurity experts, patched the vulnerability, and offered two years of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
May 31, 2023
Discovered
Nov 9, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Vermont State AGbd_3234f2a5a49275f02023-11-09Verified
- Maine State AGbd_c6058d3ab49a2b3c2023-11-09Verified
- Washington State AGbd_54ab15a9f1f46a492023-11-13 · +4dVerified
- South Carolina State AGbd_068157c5ee80ff0a2023-11-14 · +5dVerified
Show 4 more filings ↓Show fewer ↑up to 18d gap
- New Hampshire State AGbd_0c414cef662e480b2023-11-15 · +6dVerified
- HHS OCRbd_9fdd1746eaefe1732023-11-16 · +7dVerified
- California State AGbd_9f3c12779b714b642023-11-27 · +18dVerified
- Oregon State AGbd_d9f19ada2e1cd45a2023-11-27 · +18dVerified
Filing propagation · 9 filings · 8 states
View merged incident ↗Pattern: first filing Nov 9 (VT), last Nov 27 (OR) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.