State of Maine
ent_8f53b2aec1abb57b3f5c72f6
Disclosures
9
State AG · HHS OCR · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,324,118
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- State of Maine
- Normalized
- state of maine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- ⛰️New Hampshire State AGas victim2024-05-09
State of Maine filed a breach notification with New Hampshire AG on 2024-05-09. The attached PDF is empty; no breach details, dates, or data types were extracted.
- 🐻California State AGas victim2023-11-27
The State of Maine experienced a data breach involving the MOVEit file transfer tool owned by Progress Software. Cybercriminals exploited a software vulnerability to access and download files from certain state agencies between May 28 and May 29, 2023. The State became aware of the incident on May 31, 2023. Affected data may include names and Social Security numbers or taxpayer identification numbers. The State blocked internet access to the server, patched the vulnerability, engaged legal and cybersecurity experts, and offered two years of credit monitoring to affected individuals.
- 🦫Oregon State AGas victim2023-11-27
State of Maine reported a data breach to the Oregon Attorney General. The breach was reported on 2023-11-27. The breach occurred during 5/28/2023 - 5/29/2023. The breach was discovered on 5/31/2023. 1,324,118 individuals were affected. Notice was sent on 11/9/2023.
- MAINEHHS OCRas victim2023-11-16
The State of Maine reported to HHS on 2023-11-16 a Hacking/IT Incident affecting 376,504 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names, DOB, SSN, diagnoses, and claims. The CE provided complimentary credit monitoring and implemented additional safeguards.
- ⛰️New Hampshire State AGas victim2023-11-15
The State of Maine notified the New Hampshire Attorney General on November 15, 2023, regarding a cybersecurity incident involving its MOVEit file transfer software. The breach exploited a zero-day vulnerability (CVE-2023-35174) in the software, leading to unauthorized access and exfiltration of personal data affecting approximately 1.3 million individuals. The State became aware of the vulnerability on May 31, 2023, when a patch was released, but did not discover the breach until later. Affected data included Social Security numbers, taxpayer information, and other personally identifiable information. The State has begun notifying affected individuals.
- 🌲Washington State AGas victim2023-11-13
State of Maine, a government sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-31 and filed notice on 2023-11-13. 2,606 Washington residents were affected. 166 days elapsed between awareness and notification. 3 days to identify the breach. 0 days to contain the breach.
- 🍁Vermont State AGas victim2023-11-09
The State of Maine notified consumers of a data breach involving its MOVEit file transfer tool, owned by Progress Software. Cybercriminals exploited a vulnerability between May 28-29, 2023, to access and download files from certain state agencies. Affected data included names and government identifiers (SSN/TIN). The State engaged legal counsel and cybersecurity experts, patched the vulnerability, and offered two years of credit monitoring to affected individuals.
- 🦬Montana State AGas victim2023-11-09
State of Maine reported a data breach to the Montana Attorney General. The breach was reported on 2023-11-09. The breach occurred from 5/28/2023 to 5/29/2023. 232 Montana residents were affected.
- 🦞Maine State AGas victim2023-11-09
The State of Maine reported a breach of its external systems caused by a vulnerability in MOVEit software. The incident occurred May 28-29, 2023, and was discovered on May 31, 2023. The breach affected 1,324,118 individuals nationwide, including 534,194 Maine residents. Compromised data included names and driver's license numbers. Notification was provided via substitute notice on November 9, 2023, with two years of identity protection services offered.