ERNST & YOUNG LLP
bd_d769d3dcc09c3cbc · schema v1 · pii pii-v1
Full breach record for ERNST & YOUNG LLP →5 incidents on fileErnst & Young LLP (EY US) filed a supplemental notice with the New Hampshire Attorney General regarding a security incident involving a third-party service provider, Progress Software’s MOVEit Transfer solution. EY US was informed of the vulnerability on May 31, 2023. The supplemental notice identifies 629 affected New Hampshire residents, an increase from the initial 72 reported in August 2023. EY US engaged third-party security experts, secured systems, and offered credit monitoring via Experian. The investigation is now complete.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Discovered
Apr 30, 2024
Filed
vs. sector median
+29 wks slower
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Massachusetts State AGbd_acdd5c6a642710682023-08-29 · +245dVerified by operator
- South Carolina State AGbd_1a497359484fd3612023-08-28 · +246dVerified by operator
- Indiana State AGbd_74745e5983f6eb6e2023-08-24 · +250dVerified by operator
- Oregon State AGbd_43034954cfbe06cc2023-08-22 · +252dVerified
Show 6 more filings ↓Show fewer ↑up to 265d gap
- California State AGbd_342a8e17707d445d2023-08-09 · +265dVerified
- Delaware State AGbd_51121ff37fe0619a2023-08-09 · +265dVerified
- Massachusetts State AGbd_6468994aed51a5192023-08-09 · +265dVerified by operator
- Maine State AGbd_8403dcd75972f36e2023-08-09 · +265dVerified
- Indiana State AGbd_941fd2c5aa2026e22023-08-09 · +265dVerified by operator
- Montana State AGbd_962a060b07cd01d62023-08-09 · +265dVerified
Showing first 10 of 14 linked disclosures.
Filing propagation · 11 filings · 9 states
View merged incident ↗Pattern: first filing Aug 9 (CA), last Apr 30 (NH) — a 265-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 14 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.