Sovos Compliance, LLC
bd_fd9a9a297311db80 · schema v1 · pii pii-v1
Full breach record for Sovos Compliance, LLC →Sovos Compliance, LLC. filed a supplemental notice with the New Hampshire Attorney General's office on September 22, 2023, regarding 59 additional NH residents affected by a MOVEit Transfer vulnerability exploit. The incident occurred on May 30, 2023, when unauthorized actors exploited a previously unknown vulnerability to exfiltrate personal information. Sovos took the application offline, retained advisors, and notified law enforcement. Affected data includes personal information; victims are offered two years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_2644df19a41ec830California State AGfiled 2023-09-22Verified
- bd_40393771a63e8372Oregon State AGfiled 2023-09-22Verified
- bd_7d54e64352e44cf5Vermont State AGfiled 2023-09-22Verified
- bd_9c65f917da81d4d8Maine State AGfiled 2023-09-22Verified
Show 6 more filings ↓Show fewer ↑up to 30d gap
- bd_bfa8650066e49884Washington State AGfiled 2023-09-22Verified
- bd_1d16661cc5f0c5c2Maine State AGfiled 2023-09-05(17d gap)Verified
- bd_084e33a4c378d534Vermont State AGfiled 2023-08-23(30d gap)Verified
- bd_1263c3b040734745Delaware State AGfiled 2023-08-23(30d gap)Verified
- bd_186dbb4a134b0369New Hampshire State AGfiled 2023-08-23(30d gap)Verified
- bd_3d2bde1a29ed726eOregon State AGfiled 2023-08-23(30d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sovos-compliance-20230922.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- 557b1c1704983399f5d0b66e38dd815a7930c17ec9efd7ce30525f2644dc8ff7
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Sep 22, 2023
- Affected individuals
- 59
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.