HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
General Atlantic
bd_fdb7a24a8811f447 · schema v1 · pii pii-v1
Full breach record for General Atlantic →Sovos Compliance, LLC reported a security event involving Atlantic Shareholder Services on May 31, 2023. Unauthorized actors exploited a vulnerability in Progress Software's MOVEit Transfer application to download personal information. Sovos took the application offline, retained experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring via Kroll.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/10/Delaware-Exhibit-A-and-B-09-22-23.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- a82b4ee8e83bce61eb162cafca728547ce97384490566a1842abda357cda14da
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- General Atlanticnorm: general atlantic
- Domain
- generalatlantic.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Third party
- via Progress Software (MOVEit Transfer)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.