HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsBusiness Associate (HIPAA)PIIIDENTITY_BASICLowContained
BETH ISRAEL LAHEY HEALTH, INC.
bd_c6fe0e1059a7cbac · schema v1 · pii pii-v1
Full breach record for BETH ISRAEL LAHEY HEALTH, INC. →Ricoh USA, Inc. notified the NH Attorney General of a security incident affecting Beth Israel Lahey Health, Inc. customers. An unauthorized party exploited a zero-day vulnerability in Progress Software's MOVEit platform on May 31, 2023, to access and acquire files containing PII of 3 New Hampshire residents. Ricoh secured the instance, investigated, and mailed notifications on Sept 21, 2023, offering credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ricoh-usa-20230921.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 21, 2023
- Raw hash
- f5cc80730627e22e6b65050e2ac9caaa7c396247abac42d5fe85a33f00a2c61e
Reporting entity
- Name
- Ricoh, USA, Inc.norm: ricoh usa
Victim entity
- Name
- BETH ISRAEL LAHEY HEALTH, INC.norm: beth israel lahey health
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Sep 21, 2023
- Affected individuals
- 3
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Third party
- via Progress Software Corporation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(113 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.