HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
PH TECH, LLC
bd_ee4a6fc951333f4a · schema v1 · pii pii-v1
Full breach record for PH TECH, LLC →PH TECH notified New Hampshire residents of a data breach involving the MOVEit file transfer application. On May 30, 2023, attackers exploited a vulnerability in MOVEit to access personal information stored on PH TECH servers. PH TECH discovered the intrusion on June 2, 2023, took systems offline, and engaged forensic investigators. The breach exposed personal information of individuals associated with health plans served by PH TECH. PH TECH notified the FBI and Oregon State Police and offered free identity theft protection services to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_40a9ef82c057f2eeMaine State AGfiled 2023-08-11Verified
- bd_c955bd885464f272California State AGfiled 2023-08-16(5d gap)Verified
- bd_72b7c1efb706073bMontana State AGfiled 2023-08-02(9d gap)Verified
- bd_fee806c9a4452c7cOregon State AGfiled 2023-07-31(11d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 32d gap
- bd_d22af6d5b363426eOregon State AGfiled 2023-07-24(18d gap)Verified
- bd_48e51f819b175d34Washington State AGfiled 2023-07-10(32d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ph-tech-20230811.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 11, 2023
- Raw hash
- e938061e560ea40e78579f7cb88c496cf1b5dd9657ca9018784865661d8f7d6a
Reporting entity
- Name
- PH TECH, LLCnorm: ph tech
Victim entity
- Name
- PH TECH, LLCnorm: ph tech
Incident
- Discovered
- Jun 2, 2023
- Materiality determined
- —
- Notification sent
- Jul 27, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)Notified the Oregon State Police (OSP)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.