HackingTransportation & LogisticsProfessional ServicesTransportationCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryDownstream VictimsPIIIDENTITY_GOVERNMENTMediumContained
Sirva, Inc. filing on its own and on behalf of the impacted data owners (Sirva, Inc. clients)
bd_d1deff1210d0880a · schema v1 · pii pii-v1
Full breach record for Sirva, Inc. filing on its own and on behalf of the impacted data owners (Sirva, Inc. clients) →Sirva, Inc., a moving and relocation services provider, experienced an unauthorized network intrusion by unknown external actors between August 16 and October 17, 2023, during which certain files were copied. The breach was discovered on March 21, 2024 via data mining review results. Affected data included name and Social Security number. One Maine resident was impacted. Sirva notified affected individuals on June 14, 2024 and offered 12 months of Kroll credit monitoring.
Leak gap clock✗ Leak >180d12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
A leak claim by lockbit_3 about this victim predates this filing by 253 days.View originating leak claim
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/aa61a067-d49d-4973-90de-b0159c994bb8.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 14, 2024
- Raw hash
- a5fcda05dbabb32743b5bf3274ff95b9aeaeb778bf6d0b31be590de6f92e4692
Reporting entity
- Name
- Sirva, Inc. filing on its own and on behalf of the impacted data owners (Sirva, Inc. clients)norm: sirva inc filing on its own and on behalf of the impacted data owners sirva inc clients
- Domain
- sirva.com
- Industry
- Moving and Relocation Services
Victim entity
- Name
- Sirva, Inc. filing on its own and on behalf of the impacted data owners (Sirva, Inc. clients)norm: sirva inc filing on its own and on behalf of the impacted data owners sirva inc clients
- Domain
- sirva.com
- Industry
- Moving and Relocation Services
- Industry
- Transportation & LogisticsllmProfessional Servicesllm
Incident
- Discovered
- Mar 21, 2024
- Materiality determined
- —
- Notification sent
- Jun 14, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement and regulatorsNotified three major credit reporting agencies: Equifax, Experian, TransUnion
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- Leak >180dME AG >30d · 85dME resident >60d · 85d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 21, 2024→ Filed with AG: Jun 14, 202485d 30 days (soft) ME AG >30d Maine Discovered: Mar 21, 2024→ Notified: Jun 14, 202485d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.