Nuance Communications, Inc
ent_019e2172c76ac85b029a0094b0176711
Disclosures
7
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,225,054
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Nuance Communications, Inc
- Normalized
- nuance communications— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300K2IJ84JKLDX085
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🦫Oregon State AGas victim2023-09-19
Nuance Communications Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2023-09-19. The breach occurred during 5/28/2023 - 5/29/2023. The breach was discovered on 7/10/2023. 1,225,054 individuals were affected. Notice was sent on 9/18/2023.
- 💎Delaware State AGas victim2023-09-18
Nuance Communications, Inc. disclosed a security incident involving its third-party vendor, Progress Software's MOVEit Transfer software. An unauthorized third party exploited a previously unknown vulnerability (zero-day) between May 28-29, 2023, to exfiltrate data. Nuance confirmed the breach on July 11, 2023, and notified affected individuals starting August 1, 2023. Affected data included names, dates of birth, medical record numbers, gender, and radiology study details. Nuance secured servers, engaged cybersecurity experts, and notified law enforcement.
- 💎Delaware State AGas victim2023-09-18
Nuance Communications, Inc. disclosed a security incident involving its third-party vendor, Progress Software Corporation's MOVEit Transfer software. An unauthorized third party exploited a previously unknown vulnerability (0-day) in the software between May 28-29, 2023, to exfiltrate data. Nuance discovered the incident on May 31, 2023, secured its systems, and notified law enforcement. The affected data included patient names, DOB, medical record numbers, gender, and radiology study details for healthcare provider customers. Nuance notified affected individuals on August 1, 2023. This is a Delaware state AG breach notification.
- 🦞Maine State AGas victim2023-09-15
Nuance Communications, Inc. disclosed a data breach affecting one Maine resident, which occurred from May 28 to May 29, 2023. The breach was discovered on July 10, 2023, and was attributed to a zero-day vulnerability. The compromised data includes Social Security Numbers. Affected individuals were notified on September 22, 2023, and offered a 24-month membership to Equifax’s Credit Watch Gold for identity theft protection.
- ⛰️New Hampshire State AGas victim2023-09-15
Nuance Communications, Inc. notified the New Hampshire Attorney General of a security incident involving a zero-day vulnerability in Progress Software's MOVEit Transfer application. The attack occurred on May 28-29, 2023, and was discovered by Nuance on May 31, 2023. The breach impacted approximately 1,259 New Hampshire residents, exposing medical and healthcare information. Nuance took immediate response actions, including securing servers, engaging Microsoft and legal counsel, and notifying the FBI. Remediation included offering credit monitoring services to affected individuals.
- 🐻California State AGas victim2023-09-15
Nuance Communications, Inc. disclosed a data breach resulting from a previously unknown vulnerability in MOVEit Transfer software provided by third-party vendor Progress Software Corporation. An unauthorized third party exfiltrated data between May 28 and May 29, 2023. Nuance was notified of the vulnerability on May 31, 2023. Affected data included names, dates of birth, medical record numbers, gender, and details about radiology studies (provider, facility, date of service, study identifiers, and study reports). Social Security numbers and financial information were not involved. Nuance secured systems, engaged forensic experts, notified law enforcement, and sent notices to affected individuals starting August 1, 2023.
- 🦬Montana State AGas victim2023-09-15
Nuance Communications, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-09-15. The breach occurred from 5/28/2023 to 5/30/2023. 547 Montana residents were affected.