Maximus
ent_019e20d1c6573a58386e40bbfe23fb55
Disclosures
13
State AG · Leak Site · SEC 8-K · 9 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
11,000,000
nationwide · SEC 8-K FEDERAL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Maximus
- Normalized
- maximus— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 894500C4T5YA9T4L8761
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- maximus.com
Disclosure history (13)newest first
- 🥔Idaho State AGas victim2024-01-10
Maximus, Inc. submitted a supplemental data security incident update to the Idaho Attorney General on January 10, 2024, regarding a breach involving MOVEit Transfer. The incident affected 20,513 Idaho residents. Maximus offered 24 months of credit monitoring and identity restoration services through Experian and notified consumer reporting agencies. The investigation is concluded.
- 🦫Oregon State AGas victim2023-08-29
Maximus Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-29. The breach occurred during 5/27/2023 - 5/31/2023. The breach was discovered on 5/31/2023. Notice was sent on 8/24/2023.
- 💎Delaware State AGas victim2023-08-25
Maximus Health Services, Inc. notified individuals of a security incident involving the MOVEit Transfer software vulnerability. Unauthorized access occurred between May 27 and May 31, 2023, resulting in the exfiltration of personal information. Maximus took the environment offline, applied vendor patches, and is offering two years of credit monitoring services.
- 🌲Washington State AGas victim2023-08-25
Maximus, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-30 and filed notice on 2023-08-25. 70,847 Washington residents were affected. 87 days elapsed between awareness and notification. 3 days to identify the breach. 1 days to contain the breach.
- 🦬Montana State AGas victim2023-07-28
Maximus, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-28. The breach occurred from 5/27/2023 to 5/31/2023. 14,769 Montana residents were affected.
- 🥔Idaho State AGas victim2023-07-28
Maximus, Inc. notified Idaho AG on July 28, 2023, of a data breach involving its MOVEit Transfer software. An unauthorized party exploited a zero-day vulnerability in the software between May 27 and May 31, 2023, to exfiltrate files containing personal information of at least 4,852 Idaho residents. Data included names, SSNs, ITINs, DOB, and medical/insurance info. Maximus took the system offline, applied patches, notified law enforcement (FBI), and offered 24 months of credit monitoring.
- GLOBALLeak Siteas victim2023-07-26
Moving people forward - Maximus
- FEDERALSEC 8-Kas victim2023-07-26
Maximus, Inc. disclosed via Form 8-K Item 8.01 that it was affected by the MOVEit zero-day vulnerability disclosed by Progress Software on May 31, 2023. An unauthorized third party accessed personal information — including Social Security numbers and protected health information — of at least 8 to 11 million individuals tied to government program data shared via MOVEit. Maximus estimates approximately $15 million in investigation and remediation costs for Q ending June 30, 2023. Investigation ongoing.
- 🌴South Carolina State AGas victim2021-06-26
Maximus, Inc. notified Ohio healthcare providers that an unknown actor impermissibly accessed a Maximus server containing personal information (name, DOB, SSN, DEA number) starting May 17, 2021. Maximus isolated the server, engaged forensic investigators, and notified law enforcement and the Ohio Department of Medicaid. No evidence of misuse was found, but 24 months of credit monitoring via Experian was offered.
- 🦫Oregon State AGas victim2021-06-23
Maximus, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-06-23. The breach occurred during 5/17/2021 - 5/19/2021. The breach was discovered on 5/19/2021. 334,690 individuals were affected. Notice was sent on 6/18/2021.
- 🦬Montana State AGas victim2021-06-18
Maximus, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2021-06-18. The breach occurred from 5/17/2021 to 5/19/2021. 518 Montana residents were affected.
- 🌲Washington State AGas victim2021-06-18
Maximus, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2021-05-19 and filed notice on 2021-06-18. 2,560 Washington residents were affected. 30 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2021-06-18
Maximus, Inc. experienced an external system breach (hacking) between May 17, 2021, and May 19, 2021. The breach was discovered on May 19, 2021. The incident affected 886 Maine residents, compromising their names and Social Security numbers. In response, Maximus is offering two years of credit monitoring and identity protection services through Experian.