HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
EBS Services, LLC
bd_e6f677ae3f184f7e · schema v1 · pii pii-v1
Full breach record for EBS Services, LLC →Pension Benefit Information, LLC (PBI), which provides audit and address research services for EBS Services, LLC, experienced a data breach due to a vulnerability in Progress Software's MOVEit Transfer. An unauthorized third party accessed PBI's MOVEit server on May 29-30, 2023, and downloaded data including names and other data elements. PBI discovered the issue on May 31, 2023, when Progress disclosed the vulnerability. PBI patched servers, investigated the scope, and is offering identity monitoring services through Kroll.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_9bdf66298bd563f8Maine State AGfiled 2023-07-17Candidate
- bd_1ac316351547cdb6Montana State AGfiled 2023-08-10(24d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570388
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2023
- Raw hash
- 5666da033e29437b82a42a40c6c9e6aba2968a8238e4b94cfd3a84e46ec2fc07
Reporting entity
- Name
- EBS Services, LLCnorm: ebs services
Victim entity
- Name
- EBS Services, LLCnorm: ebs services
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(47 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.