HackingVulnerability ExploitCapture Stored DataData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIALMediumContained
PH TECH, LLC
bd_c955bd885464f272 · schema v1 · pii pii-v1
Full breach record for PH TECH, LLC →PH TECH disclosed a data breach involving the exploitation of a vulnerability in Progress MOVEit software. An unknown actor exploited this weakness on May 30, 2023, to exfiltrate personal information including names, SSNs, dates of birth, and health-related data (diagnosis/procedure codes). The incident was discovered on June 16, 2023. PH TECH engaged forensic experts, notified law enforcement, and offered identity theft protection services to affected individuals.
California clockDiscovered Jun 16, 2023 → Notified Aug 15, 202360d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_40a9ef82c057f2eeMaine State AGfiled 2023-08-11(5d gap)Verified
- bd_ee4a6fc951333f4aNew Hampshire State AGfiled 2023-08-11(5d gap)Verified
- bd_72b7c1efb706073bMontana State AGfiled 2023-08-02(14d gap)Verified
- bd_fee806c9a4452c7cOregon State AGfiled 2023-07-31(16d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 37d gap
- bd_d22af6d5b363426eOregon State AGfiled 2023-07-24(23d gap)Verified
- bd_48e51f819b175d34Washington State AGfiled 2023-07-10(37d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571925
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 16, 2023
- Raw hash
- 244fd1cbe9766c8d4ba267d40d5f0d56e138b5547a89af29f93d920d54b7fe45
Reporting entity
- Name
- PH TECH, LLCnorm: ph tech
Victim entity
- Name
- PH TECH, LLCnorm: ph tech
Incident
- Discovered
- Jun 16, 2023
- Materiality determined
- —
- Notification sent
- Aug 15, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 16, 2023→ Notified: Aug 15, 202360d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.