HackingSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowResolved
ERNST & YOUNG LLP
bd_d769d3dcc09c3cbc · schema v1 · pii pii-v1
Full breach record for ERNST & YOUNG LLP →Ernst & Young LLP (EY US) filed a supplemental notice with the New Hampshire Attorney General regarding a security incident involving a third-party service provider, Progress Software’s MOVEit Transfer solution. EY US was informed of the vulnerability on May 31, 2023. The supplemental notice identifies 629 affected New Hampshire residents, an increase from the initial 72 reported in August 2023. EY US engaged third-party security experts, secured systems, and offered credit monitoring via Experian. The investigation is now complete.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed629 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ernst-young-20240430.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 30, 2024
- Raw hash
- cc99059b279ede60e5e04b3248ed7c0bd5d16752c44e04742b13ec8670aff356
Reporting entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Victim entity
- Name
- ERNST & YOUNG LLPnorm: ernst young
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 9, 2023
- Affected individuals
- 629
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 48 weeks(335 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.