FEDERALItem 8.01 · voluntaryHackingVulnerability ExploitZero-DayData ExfiltratedData EncryptedData PublishedTargetedPIICREDENTIALSLowActive
Progress Software Corporation
bd_fa21d75a8ae78d4e · schema v1 · pii pii-v1
Full breach record for Progress Software Corporation →Progress Software Corporation disclosed a zero-day vulnerability (MOVEit Transfer) exploited by external actors to gain unauthorized access to customer environments. The vulnerability allowed for privilege escalation and data exfiltration. Progress engaged forensic investigators, law enforcement, and outside counsel, and released a patch on May 31, 2023. The incident is ongoing, and Progress does not believe it will have a material impact on its business.
SEC clockMateriality determined May 30, 2023 → Filed Jun 5, 20236d ✓ SEC 4-day OK8 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4a79775e8a92d996Montana State AGfiled 2023-08-18(74d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/876167/000087616723000113/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 5, 2023
- Raw hash
- fe232e51fa5d84328d04412f914209a05623e10d27d9765bda631df86f35d705
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Progress Software Corporation /MAnorm: progress software corporation ma
- SEC CIK
- 0000876167
Victim entity
- Name
- Progress Software Corporationnorm: progress software
- SEC CIK
- 0000876167
Incident
- Discovered
- May 28, 2023
- Materiality determined
- May 30, 2023
- Notification sent
- May 30, 2023
- Affected individuals
- Not disclosed
- Data types
- PIICREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Engaged with federal law enforcement and other federal agencies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 6d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: May 30, 2023→ Filed: Jun 5, 20236d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.