Sovos Compliance, LLC
ent_019e2170428f896bcf87ad9708182ac4
Disclosures
25+
State AG · HHS OCR · 10 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
215,114
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sovos Compliance, LLC
- Normalized
- sovos compliance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300M9XYG5WP2QHH07
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (newest 25)newest first
- New Hampshire State AGas reporting2023-12-01
Sovos Compliance, LLC issued a New Hampshire data breach notice on November 30, 2023, regarding an incident involving Anheuser-Busch Companies. On May 31, 2023, unauthorized actors exploited a vulnerability in the MOVEit Transfer application to download personal information. Sovos took the application offline, engaged forensic experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
- Massachusetts State AGas victim2023-09-22
Sovos Compliance LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-09-22. 522 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2023-09-22
Sovos Compliance LLC notified the California Attorney General of a security event involving its MOVEit Transfer application. On May 31, 2023, Progress Software announced a previously unknown vulnerability in MOVEit. Unauthorized actors exploited this zero-day vulnerability to download files containing personal information of Sovos customers. The breach occurred on May 27, 2023. Sovos took the application offline, activated incident response, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
- Oregon State AGas victim2023-09-22
Sovos Compliance LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-09-22. The breach occurred during 5/27/2023 - 5/30/2023. The breach was discovered on 1/1/00017/20/2023. 181,507 individuals were affected. Notice was sent on 9/22/2023.
- Vermont State AGas victim2023-09-22
Sovos Compliance, LLC notified Vermont AG that unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application to download personal information. Sovos took the application offline, engaged forensic experts, notified law enforcement, and offered two years of credit monitoring. The specific data elements are redacted in the template but include identity and government identifiers.
- Maine State AGas victim2023-09-22
A third-party service provider, Sovos Compliance LLC, experienced a data breach due to a software vulnerability. The incident occurred between May 27 and May 30, 2023, and was discovered on June 12, 2023. The breach affected 31 Maine residents, compromising their names and driver's license or non-driver ID card numbers. Sovos is offering 24 months of identity monitoring services through Kroll to those affected.
- Washington State AGas victim2023-09-22
Sovos Compliance, LLC reported unauthorized access to its MOVEit Transfer application in May 2023. The incident involved exploitation of a previously unknown vulnerability (zero-day) to exfiltrate personal information including names, SSNs, and financial data. 1,450 Washington residents were affected. Sovos engaged forensic experts, notified law enforcement, and offered two years of credit monitoring.
- New Hampshire State AGas victim2023-09-22
Sovos Compliance, LLC. filed a supplemental notice with the New Hampshire Attorney General's office on September 22, 2023, regarding 59 additional NH residents affected by a MOVEit Transfer vulnerability exploit. The incident occurred on May 30, 2023, when unauthorized actors exploited a previously unknown vulnerability to exfiltrate personal information. Sovos took the application offline, retained advisors, and notified law enforcement. Affected data includes personal information; victims are offered two years of credit monitoring.
- Delaware State AGas reporting2023-09-22
Sovos Compliance, LLC reported a security event involving Atlantic Shareholder Services on May 31, 2023. Unauthorized actors exploited a vulnerability in Progress Software's MOVEit Transfer application to download personal information. Sovos took the application offline, retained experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring via Kroll.
- Maine State AGas victim2023-09-05
Sovos Compliance LLC, a financial services software provider, reported a data breach affecting 66 Maine residents and 215,114 individuals in total. The breach occurred between May 27 and May 30, 2023, due to a software vulnerability and was discovered by Sovos on June 12, 2023. The compromised data includes names and Social Security Numbers. Sovos is offering 24 months of complimentary identity monitoring and restoration services through Kroll.
- California State AGas reporting2023-08-29
Sovos Compliance, LLC notified individuals on behalf of RoundPoint Mortgage Servicing LLC regarding a security incident stemming from the MOVEit Transfer zero-day vulnerability announced by Progress Software on May 31, 2023. Unauthorized actors exploited the vulnerability to download files containing personal information. Sovos took the affected application offline and offered two years of complimentary credit monitoring through Kroll.
- California State AGas reporting2023-08-28
Sovos Compliance, LLC, a vendor for PennyMac Loan Services, LLC, experienced a security incident on May 30, 2023, when unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application. The attackers downloaded a file containing personal information of PennyMac customers. Sovos took the application offline, activated incident response, retained experts, and notified law enforcement. Credit monitoring services are being offered to affected individuals.
- South Carolina State AGas victim2023-08-24
SOVOS Compliance, LLC notified South Carolina residents of a security event involving the MOVEit Transfer application. Unauthorized actors exploited a previously unknown vulnerability (zero-day) in the software to download personal information. SOVOS took the application offline, engaged cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
- Vermont State AGas victim2023-08-23
Sovos Compliance, LLC notified consumers that unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application to download files containing personal information. The incident was discovered after Progress announced the vulnerability on May 31, 2023. Sovos took the application offline, activated incident response procedures, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
- Delaware State AGas victim2023-08-23
Sovos Compliance LLC disclosed a security event involving the MOVEit Transfer application vulnerability discovered May 31, 2023. Unauthorized actors exploited the vulnerability to exfiltrate personal information, including government IDs and basic identity data. Sovos took the application offline, retained experts, notified law enforcement, and offers two years of credit monitoring via Kroll.
- New Hampshire State AGas victim2023-08-23
Sovos Compliance, LLC notified New Hampshire regulators of a security event involving the MOVEit Transfer application. On May 31, 2023, unauthorized actors exploited a previously unknown vulnerability in the software to download personal information. Sovos took the application offline, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
- Oregon State AGas victim2023-08-23
Sovos Compliance LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-23. The breach occurred during 5/27/2023 - 5/30/2023. The breach was discovered on 7/20/2023. 215,114 individuals were affected. Notice was sent on 8/23/2023.
- Maine State AGas victim2023-08-23
Sovos Compliance LLC reported a data breach affecting Maine residents due to a software vulnerability. The breach, which occurred between May 27 and May 30, 2023, resulted in the compromise of names and driver's license or non-driver identification card numbers. The company discovered the incident on June 12, 2023, and began notifying affected individuals on August 23, 2023. Impacted individuals were offered 24 months of complimentary identity monitoring services through Kroll.
- Washington State AGas victim2023-08-23
Sovos Compliance, LLC disclosed a security event involving the MOVEit Transfer application vulnerability discovered May 31, 2023. Unauthorized actors exploited the vulnerability to download personal information of individuals associated with unclaimed property claims. Sovos took the application offline, retained experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring via Kroll.
- California State AGas victim2023-08-23
Sovos Compliance LLC disclosed a security event involving the exploitation of a previously unknown vulnerability in Progress Software's MOVEit Transfer application. Unauthorized actors exploited this zero-day vulnerability to download files containing personal information of individuals associated with unclaimed property claims. The breach occurred on May 27, 2023, and was discovered on May 31, 2023. Sovos took the application offline, activated incident response procedures, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
- Montana State AGas reporting2023-08-21
Sovos Compliance, LLC disclosed a security incident involving its vendor Progress Software's MOVEit Transfer application. Unauthorized actors exploited a previously unknown vulnerability (zero-day) on May 30, 2023, to exfiltrate personal information belonging to customers of PennyMac Loan Services, LLC. Sovos notified PennyMac on July 28, 2023, and offered credit monitoring services.
- MASSACHUSETTSHHS OCRas victim2023-08-08
Sovos Compliance LLC reported to HHS on 2023-08-08 a Hacking/IT Incident affecting 18261 individuals. Breached information located on Network Server. A vulnerability in the business associate's software application impacted PHI including names, SSNs, addresses, DOBs, emails, and financial/claims data.
- Montana State AGas victim2023-08-07
Sovos Compliance, LLC notified Montana residents of a security event involving the MOVEit Transfer application. Unauthorized actors exploited a previously unknown vulnerability in the application to download personal information. Sovos took the application offline, engaged cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
- Maine State AGas victim2023-07-13
Sovos Compliance LLC reported an external system breach (hacking) occurring between May 27 and May 30, 2023, discovered on June 12, 2023. The incident affected 18,513 individuals, including 52 Maine residents. Acquired data included names and Social Security Numbers. Notification was sent on July 12, 2023, offering 24 months of Kroll identity monitoring services.
- Massachusetts State AGas victim2023-07-13
Sovos Compliance LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-13. 901 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- Sovos Compliance, LLC’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).