HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICHEALTH_BASICLowContained
Medical Eye Services, Inc.
bd_e353aefdc5628e28 · schema v1 · pii pii-v1
Full breach record for Medical Eye Services, Inc. →Medical Eye Services, Inc. (MESVision) disclosed that an unauthorized individual exploited a vulnerability in its MOVEit file-transfer server to exfiltrate information on May 28 and May 31, 2023. The company discovered the incident on August 23, 2023. Affected data may include personal information of individuals enrolled in vision benefit plans. MESVision took the server offline, engaged a cybersecurity firm, reported to the FBI, and is offering credit monitoring services.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_98132492ce988ce0Maine State AGfiled 2024-01-31(1d gap)Verified
- bd_57de58eb876f18d7New Hampshire State AGfiled 2023-11-22(69d gap)Verified
- bd_6beb8ba0bda9123fCalifornia State AGfiled 2023-11-17(74d gap)Verified
- bd_8695a245d6b38536Maine State AGfiled 2023-11-17(74d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 77d gap
- bd_b9bc0c3a55fd236eOregon State AGfiled 2023-11-17(74d gap)Verified
- bd_c0b9305f53e1673eMaine State AGfiled 2023-11-15(76d gap)Verified
- bd_8fd3b5758701dc53California State AGfiled 2023-11-14(77d gap)Verified
- bd_97132facec254d63Montana State AGfiled 2023-11-14(77d gap)Candidate
- bd_bac779c9da975873Oregon State AGfiled 2023-11-14(77d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-580194
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2024
- Raw hash
- 893ad862ddf14f20daf08b9a74398ed1730ce35d00269e4251debb5c9f1c5740
Reporting entity
- Name
- Medical Eye Services, Inc.norm: medical eye
- Domain
- medeye.net
Victim entity
- Name
- Medical Eye Services, Inc.norm: medical eye
- Domain
- medeye.net
Incident
- Discovered
- Aug 23, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the incident to the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(160 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.