HackingVulnerability ExploitData MishandlingSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Amwins Group, Inc
bd_fa4ef9f24b61fdd7 · schema v1 · pii pii-v1
Full breach record for Amwins Group, Inc →Amwins Group, Inc. notified consumers of a data breach involving its HR vendor Paycor, which used Progress MOVEit Transfer. Vulnerabilities exploited in May/June 2023 allowed unauthorized access. Affected data includes names and government IDs. Amwins offered Experian credit monitoring. No direct access to Amwins' network occurred.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_494dc4f2e1e88dbcNew Hampshire State AGfiled 2024-02-02Verified
- bd_1e5fed19d3e26a44New Hampshire State AGfiled 2023-12-29(35d gap)Verified
- bd_86839945290c0ec8Vermont State AGfiled 2023-12-29(35d gap)Candidate
- bd_95c48c0e1cca7533Indiana State AGfiled 2023-12-29(35d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 35d gap
- bd_beecf0a6961d7044California State AGfiled 2023-12-29(35d gap)Candidate
- bd_e6c0b9eb96a4ff02Maine State AGfiled 2023-12-29(35d gap)Verified
- bd_ee253a334c2463a5Montana State AGfiled 2023-12-29(35d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-02-02-amwins-group-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 2, 2024
- Raw hash
- d948b3f8082fe90deb337fe3c239774cc916a318fe45f322a2c08185ae94ceb1
Reporting entity
- Name
- Amwins Group, Incnorm: amwins group
Victim entity
- Name
- Amwins Group, Incnorm: amwins group
Incident
- Discovered
- Nov 30, 2023
- Materiality determined
- —
- Notification sent
- Feb 2, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Third party
- via Paycor, Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.