HackingVulnerability ExploitData ExfiltratedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Andesa
bd_d272e85e64f9ed58 · schema v1 · pii pii-v1
Full breach record for Andesa →Andesa Services notified consumers of a data breach involving the MOVEit Transfer tool, exploited via a previously unknown vulnerability (Progress Software Corp). Unauthorized access occurred May 30-31, 2023. Data accessed included PII and government IDs. Andesa engaged third-party cybersecurity specialists, applied patches, and offered credit monitoring. 406 Rhode Island residents were explicitly identified as affected.
Vermont clock✗ VT AG >45 bday21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 122 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_bee424cd2ef287e6Leak Sitedispossessorfiled 2023-08-27(57d gap)Verified by operator
- bd_387b6476cd49ce4cLeak Sitecl0pfiled 2023-06-23(122d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-23-andesa-services-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 23, 2023
- Raw hash
- 6ad7be354396317c25d19d5d321061b7e79be568f9ef3a052a97810102c31450
Reporting entity
- Name
- Andesanorm: andesa
- Domain
- andesaservices.com
Victim entity
- Name
- Andesanorm: andesa
- Domain
- andesaservices.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Oct 23, 2023
- Affected individuals
- 406
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(145 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.