HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICPIILowContained
Amwins Group, Inc
bd_beecf0a6961d7044 · schema v1 · pii pii-v1
Full breach record for Amwins Group, Inc →Amwins Group, Inc. notified employees of a data security event involving its HR vendor, Paycor, Inc., and its file transfer provider, Progress MOVEit. An unauthorized actor exploited previously unknown vulnerabilities in MOVEit Transfer to access servers used by Paycor. Amwins received notification on November 30, 2023. The incident affected employee personal information, including names and other data. Amwins conducted an internal review and is offering credit monitoring services. No unauthorized access to Amwins' own network occurred.
California clockDiscovered Nov 30, 2023 → Notified Dec 29, 202329d ✓ CA 60-day OK29 days discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_1e5fed19d3e26a44New Hampshire State AGfiled 2023-12-29Verified
- bd_86839945290c0ec8Vermont State AGfiled 2023-12-29Candidate
- bd_95c48c0e1cca7533Indiana State AGfiled 2023-12-29Verified
- bd_e6c0b9eb96a4ff02Maine State AGfiled 2023-12-29Verified
Show 3 more filings ↓Show fewer ↑up to 35d gap
- bd_ee253a334c2463a5Montana State AGfiled 2023-12-29Verified by operator
- bd_494dc4f2e1e88dbcNew Hampshire State AGfiled 2024-02-02(35d gap)Verified
- bd_fa4ef9f24b61fdd7Vermont State AGfiled 2024-02-02(35d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578587
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 29, 2023
- Raw hash
- 168aa68ff214a3e84af848140ff4c95849e8fa4a860813f6dd6a0f8ea1271e71
Reporting entity
- Name
- Amwins Group, Incnorm: amwins group
Victim entity
- Name
- Amwins Group, Incnorm: amwins group
Incident
- Discovered
- Nov 30, 2023
- Materiality determined
- —
- Notification sent
- Dec 29, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Paycor, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 30, 2023→ Notified: Dec 29, 202329d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.