Sovos Compliance, LLC
bd_d17588a3ca1a3962 · schema v1 · pii pii-v1
Full breach record for Sovos Compliance, LLC →Sovos Compliance LLC disclosed a security event involving the exploitation of a previously unknown vulnerability in Progress Software's MOVEit Transfer application. Unauthorized actors exploited this zero-day vulnerability to download files containing personal information of individuals associated with unclaimed property claims. The breach occurred on May 27, 2023, and was discovered on May 31, 2023. Sovos took the application offline, activated incident response procedures, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_084e33a4c378d534Vermont State AGfiled 2023-08-23Verified
- bd_1263c3b040734745Delaware State AGfiled 2023-08-23Verified
- bd_186dbb4a134b0369New Hampshire State AGfiled 2023-08-23Verified
- bd_1d16661cc5f0c5c2Maine State AGfiled 2023-09-05(13d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 30d gap
- bd_2644df19a41ec830California State AGfiled 2023-09-22(30d gap)Verified
- bd_40393771a63e8372Oregon State AGfiled 2023-09-22(30d gap)Verified
- bd_7d54e64352e44cf5Vermont State AGfiled 2023-09-22(30d gap)Verified
- bd_9c65f917da81d4d8Maine State AGfiled 2023-09-22(30d gap)Verified
- bd_bfa8650066e49884Washington State AGfiled 2023-09-22(30d gap)Verified
- bd_fd9a9a297311db80New Hampshire State AGfiled 2023-09-22(30d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572310
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2023
- Raw hash
- e8ade52c5be8a38fc93339f7f9d29977188bb54fd833548067175c9dccd54970
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.