DisclosureLens
HackingTechnologyInformationVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Government IDFinancial accountMediumContained

Ricoh USA, Inc.

bd_c6fe0e1059a7cbac · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Sep 21, 2023

To disclose

16 weeks

Affected

3state residents only

Confidence

67%

Ricoh USA, Inc. notified the NH Attorney General of a security incident involving 3 New Hampshire residents. On May 31, 2023, Progress Software Corporation notified customers of a zero-day vulnerability in the MOVEit managed file transfer platform. An unauthorized party exploited this vulnerability to access and acquire data from Ricoh's MOVEit instance. The compromised data may have included names, addresses, Social Security numbers, and financial account information. Ricoh secured its instance, conducted an investigation, and is offering credit monitoring to affected individuals.

Incident timeline

discovery → filing · 16 weeks / 113 days

May 31, 2023

Discovered

Sep 21, 2023

Filed

vs. sector median

2 wks faster

Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.