HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
University of Rochester
bd_f7935ffb9c85c7d1 · schema v1 · pii pii-v1
Full breach record for University of Rochester →University of Rochester notified individuals of a data breach involving its third-party vendor, Progress Software. An unauthorized party exploited a vulnerability in the MOVEit File Transfer solution between May 27 and May 31, 2023, to access and potentially exfiltrate personal information, including Social Security numbers. The University engaged outside professionals to investigate and is offering 24 months of complimentary identity protection services.
California clockDiscovered May 31, 2023 → Notified Jul 28, 202358d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_7d744ab9ef9b3c31Leak Sitecl0pfiled 2023-07-14(13d gap)Verified
Regulatory filings (3) · sorted by filing gap
- bd_419f463a975f38c7Vermont State AGfiled 2023-07-28Verified
- bd_659d73894032e3aeMaine State AGfiled 2023-07-28Verified
- bd_8283f86271ea7a05Montana State AGfiled 2023-07-28Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570999
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- 5072d950b8842a11140525355a4e323b4db2e2acdd88a1bfd261efcb8acfc868
Reporting entity
- Name
- University of Rochesternorm: university of rochester
- Domain
- rochester.edu
Victim entity
- Name
- University of Rochesternorm: university of rochester
- Domain
- rochester.edu
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Jul 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 58d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Jul 28, 202358d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.