HackingVulnerability ExploitZero-DayData ExfiltratedData PublishedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
MAXIMUS, Inc.
bd_fe9387821fda9264 · schema v1 · pii pii-v1
Full breach record for MAXIMUS, Inc. →Maximus, Inc. notified the New Hampshire Attorney General of a data security incident involving its MOVEit Transfer environment. An unauthorized party exploited a critical zero-day vulnerability in the third-party software (Progress Software) between May 27 and May 31, 2023, to exfiltrate files containing personal information of at least 6,376 New Hampshire residents. Maximus detected the activity on May 30, 2023, took the system offline, and began notifying residents on August 24, 2023. Remediation included credit monitoring via Experian and cooperation with the FBI.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_67d6131ab83daa01Vermont State AGfiled 2023-08-25Verified
- bd_97027e573fc51e13Delaware State AGfiled 2023-08-25Verified
- bd_d3d3db6e2dd7a7a8Hawaii State AGfiled 2023-08-26(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/maximus-20230825.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2023
- Raw hash
- ba619f37fe4adf11e44165f43b0ba6ce9e8f6672673d00169cfa9c7d0b319413
Reporting entity
- Name
- MAXIMUS, Inc.norm: maximus
Victim entity
- Name
- MAXIMUS, Inc.norm: maximus
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- Aug 24, 2023
- Affected individuals
- 6,376
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.