HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CBIZ, INC.
bd_bc1e70e9424da1a0 · schema v1 · pii pii-v1
Full breach record for CBIZ, INC. →CBIZ, Inc. notified California residents of a data breach involving its IT environment for client Mayer Hoffman McCann P.C. An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software, accessing a server between May 29 and June 5, 2023, and downloading data. Affected information includes names, dates of birth, and Social Security numbers. CBIZ patched the vulnerability and is offering two years of identity monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_6a0c7d61fabe79e4Leak Sitemeowfiled 2024-06-22(295d gap)Verified
Regulatory filings (3) · sorted by filing gap
- bd_b2aef612a1f1ebc8Maine State AGfiled 2023-09-01Verified
- bd_f5753075017fc529Vermont State AGfiled 2023-09-01Verified
- bd_a81b1fd6324d50b1Maine State AGfiled 2023-12-29(119d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572787
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2023
- Raw hash
- 934883f2c4c8c62fd9708a8545780d12520a2050a17e296f796d45804eb9be78
Reporting entity
- Name
- CBIZ, INC.norm: cbiz
- Domain
- cbiz.com
Victim entity
- Name
- CBIZ, INC.norm: cbiz
- Domain
- cbiz.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.