MAXIMUS, Inc.
ent_01a00cef0a0a29c43667a1c74a6ebf6a
Disclosures
25+
State AG · HHS OCR · Leak Site · SEC 8-K · 16 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
9,179,390
nationwide · HHS OCR VA
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- MAXIMUS, Inc.
- Normalized
- maximus— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DQCDS8HJ7QF202
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- maximus.com
Disclosure history (newest 25)newest first
- Massachusetts State AGas victim2026-07-28
Maximus US Services, Inc. notified Nebraska Medicaid providers and enrollees of a security incident involving the Nebraska Provider Data Management System (PDMS). On April 27, 2026, Maximus learned of the incident and engaged forensic investigators. Personal information including names, dates of birth, and Social Security numbers may have been impacted. Maximus notified law enforcement and offered 24 months of credit monitoring via Experian.
- VIRGINIAHHS OCRas victim2025-04-25
Maximus, Inc. reported to HHS on 2025-04-25 a Unauthorized Access/Disclosure affecting 4955 individuals. Breached information located on Network Server. Business Associate present.
- Idaho State AGas victim2024-01-10
Maximus, Inc. submitted a supplemental data security incident update to the Idaho Attorney General on January 10, 2024, regarding a breach involving MOVEit Transfer. The incident affected 20,513 Idaho residents. Maximus offered 24 months of credit monitoring and identity restoration services through Experian and notified consumer reporting agencies. The investigation is concluded.
- Oregon State AGas victim2023-08-29
Maximus Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-29. The breach occurred during 5/27/2023 - 5/31/2023. The breach was discovered on 5/31/2023. Notice was sent on 8/24/2023.
- South Carolina State AGas victim2023-08-29
Maximus Health Services, Inc. disclosed a security incident involving the MOVEit Transfer vulnerability (Progress Software). Unauthorized access occurred May 27-31, 2023, resulting in the exfiltration of personal information. Maximus detected the incident on May 30, 2023, took systems offline, engaged forensic experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
- Hawaii State AGas victim2023-08-26
Maximus Health Services, Inc. notified Hawaii residents of a security incident involving the MOVEit Transfer application. Unauthorized access occurred May 27-31, 2023, exploiting a previously unknown vulnerability. Personal information was copied. Maximus took the system offline, engaged forensic experts, and offered two years of credit monitoring.
- Vermont State AGas victim2023-08-25
Maximus Health Services, Inc. notified consumers of a data breach involving Progress Software's MOVEit Transfer application. An unauthorized party accessed files between May 27-31, 2023, exploiting a vulnerability in the third-party software. Personal information was accessed. Maximus engaged forensic experts, took systems offline, and is offering two years of credit monitoring.
- Delaware State AGas victim2023-08-25
Maximus Health Services, Inc. disclosed a security incident involving the MOVEit Transfer vulnerability (Zero Day). Unauthorized access occurred between May 27-31, 2023, resulting in the exfiltration of personal information. Maximus detected the activity on May 30, 2023, took the system offline, and offered two years of credit monitoring. The incident involved a third-party software vulnerability exploited by an external actor.
- Washington State AGas victim2023-08-25
Maximus, Inc. reported a supplemental data security incident to Washington AG regarding unauthorized access to MOVEit Transfer files between May 27-31, 2023. The incident involved a zero-day vulnerability in the third-party software. 70,847 Washington residents were notified on August 24, 2023, receiving 24 months of credit monitoring. Data included names, addresses, DOBs, and SSNs.
- New Hampshire State AGas victim2023-08-25
Maximus, Inc. notified the New Hampshire Attorney General of a data security incident involving its MOVEit Transfer environment. An unauthorized party exploited a critical zero-day vulnerability in the third-party software (Progress Software) between May 27 and May 31, 2023, to exfiltrate files containing personal information of at least 6,376 New Hampshire residents. Maximus detected the activity on May 30, 2023, took the system offline, and began notifying residents on August 24, 2023. Remediation included credit monitoring via Experian and cooperation with the FBI.
- Indiana State AGas victim2023-08-24
Maximus, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-27 and was reported on 2023-08-24. 40,470 Indiana residents were affected.
- California State AGas victim2023-08-18
Maximus Human Services, Inc. disclosed that an unauthorized party exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application to access files containing personal information. The incident occurred between May 27 and May 31, 2023, and was detected on May 30, 2023. Maximus took the application offline, applied patches, engaged forensic experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services.
- VIRGINIAHHS OCRas victim2023-08-04
Maximus, Inc. reported to HHS on 2023-08-04 a Hacking/IT Incident affecting 9,179,390 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names and claims information.
- Massachusetts State AGas victim2023-07-28
Maximus, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-28. 58,800 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-07-28
Maximus Human Services, Inc. notified Montana residents of a breach involving unauthorized access to MOVEit Transfer files. The incident, stemming from a vulnerability in Progress Software's MOVEit application, occurred between May 27-31, 2023, and was detected on May 30, 2023. Personal information including names and government IDs was accessed. Maximus engaged forensic experts, patched the system, and offered 24 months of credit monitoring.
- Idaho State AGas victim2023-07-28
Maximus, Inc. notified Idaho AG on July 28, 2023, of a data breach involving its MOVEit Transfer software. An unauthorized party exploited a zero-day vulnerability in the software between May 27 and May 31, 2023, to exfiltrate files containing personal information of at least 4,852 Idaho residents. Data included names, SSNs, ITINs, DOB, and medical/insurance info. Maximus took the system offline, applied patches, notified law enforcement (FBI), and offered 24 months of credit monitoring.
- GLOBALLeak Siteas victim2023-07-26
Moving people forward - Maximus
- FEDERALSEC 8-Kas victim2023-07-26
Maximus, Inc. disclosed via Form 8-K Item 8.01 that it was affected by the MOVEit zero-day vulnerability disclosed by Progress Software on May 31, 2023. An unauthorized third party accessed personal information — including Social Security numbers and protected health information — of at least 8 to 11 million individuals tied to government program data shared via MOVEit. Maximus estimates approximately $15 million in investigation and remediation costs for Q ending June 30, 2023. Investigation ongoing.
- Indiana State AGas victim2023-06-28
Maximus US Services, Inc reported a data breach to the Indiana Attorney General. 1 Indiana residents were affected.
- Indiana State AGas victim2023-04-18
Maximus US Services, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-27 and was reported on 2023-04-18. 1 Indiana residents were affected.
- Illinois State AGas victim2023-01-01
MAXIMUS, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-499). The register records the breach as discovered on May 27, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2022-10-28
Maximus Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-10-28. 13 Massachusetts residents were affected. The report records the breach type as electronic.
- South Carolina State AGas victim2021-06-26
Maximus, Inc. notified Ohio healthcare providers that an unknown actor impermissibly accessed a Maximus server containing personal information (name, DOB, SSN, DEA number) starting May 17, 2021. Maximus isolated the server, engaged forensic investigators, and notified law enforcement and the Ohio Department of Medicaid. No evidence of misuse was found, but 24 months of credit monitoring via Experian was offered.
- Massachusetts State AGas victim2021-06-23
Maximus, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-06-23. 2,531 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2021-06-23
Maximus, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-06-23. The breach occurred during 5/17/2021 - 5/19/2021. The breach was discovered on 5/19/2021. 334,690 individuals were affected. Notice was sent on 6/18/2021.