Sovos Compliance, LLC
ent_019e2170428f896bcf87ad9708182ac4
Disclosures
25+
State AG · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
215,114
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sovos Compliance, LLC
- Normalized
- sovos compliance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300M9XYG5WP2QHH07
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (newest 25)newest first
- ⛰️New Hampshire State AGas reporting2023-12-01
Sovos Compliance, LLC issued a New Hampshire data breach notice on November 30, 2023, regarding an incident involving Anheuser-Busch Companies. On May 31, 2023, unauthorized actors exploited a vulnerability in the MOVEit Transfer application to download personal information. Sovos took the application offline, engaged forensic experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
- 🐻California State AGas victim2023-09-22
Sovos Compliance LLC notified the California Attorney General of a security event involving its MOVEit Transfer application. On May 31, 2023, Progress Software announced a previously unknown vulnerability in MOVEit. Unauthorized actors exploited this zero-day vulnerability to download files containing personal information of Sovos customers. The breach occurred on May 27, 2023. Sovos took the application offline, activated incident response, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
- 🦫Oregon State AGas victim2023-09-22
Sovos Compliance LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-09-22. The breach occurred during 5/27/2023 - 5/30/2023. The breach was discovered on 1/1/00017/20/2023. 181,507 individuals were affected. Notice was sent on 9/22/2023.
- 🍁Vermont State AGas victim2023-09-22
Sovos Compliance, LLC notified Vermont AG that unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application to download personal information. Sovos took the application offline, engaged forensic experts, notified law enforcement, and offered two years of credit monitoring. The specific data elements are redacted in the template but include identity and government identifiers.
- 🦞Maine State AGas victim2023-09-22
A third-party service provider, Sovos Compliance LLC, experienced a data breach due to a software vulnerability. The incident occurred between May 27 and May 30, 2023, and was discovered on June 12, 2023. The breach affected 31 Maine residents, compromising their names and driver's license or non-driver ID card numbers. Sovos is offering 24 months of identity monitoring services through Kroll to those affected.
- 🌲Washington State AGas victim2023-09-22
Sovos Compliance, LLC, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-12 and filed notice on 2023-09-22. 1,450 Washington residents were affected. 102 days elapsed between awareness and notification. 16 days to identify the breach. 0 days to contain the breach.
- ⛰️New Hampshire State AGas victim2023-09-22
Sovos Compliance, LLC. filed a supplemental notice with the New Hampshire Attorney General's office on September 22, 2023, regarding 59 additional NH residents affected by a MOVEit Transfer vulnerability exploit. The incident occurred on May 30, 2023, when unauthorized actors exploited a previously unknown vulnerability to exfiltrate personal information. Sovos took the application offline, retained advisors, and notified law enforcement. Affected data includes personal information; victims are offered two years of credit monitoring.
- 💎Delaware State AGas reporting2023-09-22
Sovos Compliance, LLC reported a security event involving Atlantic Shareholder Services on May 31, 2023. Unauthorized actors exploited a vulnerability in Progress Software's MOVEit Transfer application to download personal information. Sovos took the application offline, retained experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring via Kroll.
- 🦞Maine State AGas victim2023-09-05
Sovos Compliance LLC, a financial services software provider, reported a data breach affecting 66 Maine residents and 215,114 individuals in total. The breach occurred between May 27 and May 30, 2023, due to a software vulnerability and was discovered by Sovos on June 12, 2023. The compromised data includes names and Social Security Numbers. Sovos is offering 24 months of complimentary identity monitoring and restoration services through Kroll.
- 🐻California State AGas reporting2023-08-28
Sovos Compliance, LLC, a vendor for PennyMac Loan Services, LLC, experienced a security incident on May 30, 2023, when unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application. The attackers downloaded a file containing personal information of PennyMac customers. Sovos took the application offline, activated incident response, retained experts, and notified law enforcement. Credit monitoring services are being offered to affected individuals.
- 🍁Vermont State AGas victim2023-08-23
Sovos Compliance, LLC notified Vermont AG that unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application on May 31, 2023. The incident involved the exfiltration of personal information, including names and government identifiers, from unclaimed property claim records. Sovos took the application offline, engaged forensic experts, notified law enforcement, and is offering two years of credit monitoring services to affected individuals.
- 💎Delaware State AGas victim2023-08-23
Sovos Compliance LLC disclosed a security event involving the MOVEit Transfer application vulnerability discovered May 31, 2023. Unauthorized actors exploited the vulnerability to exfiltrate personal information, including government IDs and basic identity data. Sovos took the application offline, retained experts, notified law enforcement, and offers two years of credit monitoring via Kroll.
- ⛰️New Hampshire State AGas victim2023-08-23
Sovos Compliance, LLC notified New Hampshire regulators of a security event involving the MOVEit Transfer application. On May 31, 2023, unauthorized actors exploited a previously unknown vulnerability in the software to download personal information. Sovos took the application offline, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
- 🦫Oregon State AGas victim2023-08-23
Sovos Compliance LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-23. The breach occurred during 5/27/2023 - 5/30/2023. The breach was discovered on 7/20/2023. 215,114 individuals were affected. Notice was sent on 8/23/2023.
- 🦞Maine State AGas victim2023-08-23
Sovos Compliance LLC reported a data breach affecting Maine residents due to a software vulnerability. The breach, which occurred between May 27 and May 30, 2023, resulted in the compromise of names and driver's license or non-driver identification card numbers. The company discovered the incident on June 12, 2023, and began notifying affected individuals on August 23, 2023. Impacted individuals were offered 24 months of complimentary identity monitoring services through Kroll.
- 🌲Washington State AGas victim2023-08-23
Sovos Compliance, LLC, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-12 and filed notice on 2023-08-23. 11,103 Washington residents were affected. 72 days elapsed between awareness and notification. 16 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2023-08-23
Sovos Compliance LLC disclosed a security event involving the exploitation of a previously unknown vulnerability in Progress Software's MOVEit Transfer application. Unauthorized actors exploited this zero-day vulnerability to download files containing personal information of individuals associated with unclaimed property claims. The breach occurred on May 27, 2023, and was discovered on May 31, 2023. Sovos took the application offline, activated incident response procedures, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
- 🦬Montana State AGas victim2023-08-07
Sovos Compliance, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-07. The breach occurred on 5/30/2023. 189 Montana residents were affected.
- 🐻California State AGas reporting2023-07-22
Northwestern Mutual reported a data breach involving its vendor Progress Software's MOVEit Transfer application. On May 31, 2023, Progress announced a previously unknown vulnerability (zero-day) in MOVEit. Unauthorized actors exploited this vulnerability to download files containing personal information of Northwestern Mutual clients. The company took the application offline, activated incident response, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services via Kroll. The incident is contained.
- 🦞Maine State AGas victim2023-07-13
Sovos Compliance LLC reported an external system breach (hacking) occurring between May 27 and May 30, 2023, discovered on June 12, 2023. The incident affected 18,513 individuals, including 52 Maine residents. Acquired data included names and Social Security Numbers. Notification was sent on July 12, 2023, offering 24 months of Kroll identity monitoring services.
- 🐻California State AGas victim2023-07-13
Sovos Compliance, LLC notified the California AG of a security event where unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application. The breach occurred between May 27 and May 30, 2023, and was discovered on May 31, 2023. Personal information, including names and potentially Social Security numbers, was exfiltrated. Sovos took the application offline, engaged forensic experts, notified law enforcement, and offered two years of identity monitoring to affected individuals.
- 🦬Montana State AGas victim2023-07-12
Sovos Compliance, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-12. The breach occurred on 5/30/2023. 237 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2023-07-12
Sovos Compliance, LLC reported that unauthorized actors exploited a previously unknown vulnerability (zero-day) in Progress Software's MOVEit Transfer application on May 30, 2023, to download personal information. Sovos detected the incident on May 31, 2023, took the application offline, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of identity monitoring.
- 🍁Vermont State AGas victim2023-07-12
Sovos Compliance, LLC notified consumers that unauthorized actors exploited a previously unknown vulnerability in MOVEit Transfer on May 30, 2023, to download personal information. Sovos took the application offline, engaged cybersecurity experts, and notified law enforcement. Two years of complimentary identity monitoring services were offered to affected individuals.
- 💎Delaware State AGas victim2023-07-12
Sovos Compliance, LLC disclosed a security event involving the MOVEit Transfer application vulnerability discovered on May 31, 2023. Unauthorized actors exploited the vulnerability to download personal information of individuals associated with unclaimed property claims. Sovos took the application offline, retained cybersecurity experts, notified law enforcement, and is offering two years of complimentary credit monitoring and identity restoration services through Kroll.