CBIZ, INC.
bd_f5753075017fc529 · schema v1 · pii pii-v1
Full breach record for CBIZ, INC. →7 incidents on fileCBIZ, Inc. disclosed a data breach involving its MOVEit Transfer server, exploited via a vulnerability in Progress Software's software. Unauthorized access occurred between May 29 and June 5, 2023, resulting in the exfiltration of names, dates of birth, and Social Security numbers. CBIZ patched the vulnerability and offered two years of identity monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
May 29, 2023
Begins
May 31, 2023
Discovered
Sep 1, 2023
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Maine State AGbd_b2aef612a1f1ebc82023-09-01Verified by operator
- California State AGbd_bc1e70e9424da1a02023-09-01Verified by operator
- HHS OCRbd_b21836f9b07f5b0e2023-11-10 · +70dVerified by operator
- Maine State AGbd_a81b1fd6324d50b12023-12-29 · +119dVerified by operator
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Sep 1 (ME), last Dec 29 (ME) — a 119-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.