State of Maine
ent_8f53b2aec1abb57b3f5c72f6
Disclosures
11
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,324,118
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- State of Maine
- Normalized
- state of maine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (11)newest first
- New Hampshire State AGas victim2024-05-09
Supplemental notice on behalf of the State of Maine regarding the MOVEit data security incident. The vulnerability was exploited between May 28-29, 2023. The State discovered the incident on May 31, 2023. Initial notifications began November 9, 2023. A revised count identifies 10,848 New Hampshire residents affected. Data types include PII and government IDs. Credit monitoring was offered.
- Massachusetts State AGas victim2023-12-01
State of Maine reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-01. 9,582 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2023-11-27
The State of Maine experienced a data breach involving the MOVEit file transfer tool owned by Progress Software. Cybercriminals exploited a software vulnerability to access and download files from certain state agencies between May 28 and May 29, 2023. The State became aware of the incident on May 31, 2023. Affected data may include names and Social Security numbers or taxpayer identification numbers. The State blocked internet access to the server, patched the vulnerability, engaged legal and cybersecurity experts, and offered two years of credit monitoring to affected individuals.
- Oregon State AGas victim2023-11-27
State of Maine reported a data breach to the Oregon Attorney General. The breach was reported on 2023-11-27. The breach occurred during 5/28/2023 - 5/29/2023. The breach was discovered on 5/31/2023. 1,324,118 individuals were affected. Notice was sent on 11/9/2023.
- MAINEHHS OCRas victim2023-11-16
The State of Maine reported to HHS on 2023-11-16 a Hacking/IT Incident affecting 376,504 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names, DOB, SSN, diagnoses, and claims. The CE provided complimentary credit monitoring and implemented additional safeguards.
- New Hampshire State AGas victim2023-11-15
The State of Maine notified New Hampshire AG of a MOVEit vulnerability exploitation incident. Access occurred May 28-29, 2023; discovered May 31, 2023. 8,927 NH residents affected. Data included PII and SSNs. Remediation included patching and engaging counsel/experts.
- South Carolina State AGas victim2023-11-14
The State of Maine notified individuals of a data breach involving its MOVEit file transfer tool. The vulnerability was exploited between May 28-29, 2023. The State discovered the incident on May 31, 2023. Affected data included names and government identifiers (SSN/TIN). The State engaged legal counsel and cybersecurity experts, patched the vulnerability, and offered two years of credit monitoring.
- Washington State AGas victim2023-11-13
Supplemental notice on behalf of the State of Maine regarding the MOVEit data security incident. The State discovered a vulnerability in MOVEit on May 31, 2023. Cybercriminals exploited the vulnerability to access and download files between May 28-29, 2023. The incident affected 2,606 Washington residents, involving PII, SSNs, and medical information. The State engaged legal counsel and forensic experts, patched the vulnerability, and provided two years of credit monitoring.
- Vermont State AGas victim2023-11-09
The State of Maine notified consumers of a data breach involving its MOVEit file transfer tool, owned by Progress Software. Cybercriminals exploited a vulnerability between May 28-29, 2023, to access and download files from certain state agencies. Affected data included names and government identifiers (SSN/TIN). The State engaged legal counsel and cybersecurity experts, patched the vulnerability, and offered two years of credit monitoring to affected individuals.
- Montana State AGas victim2023-11-09
The State of Maine disclosed a cybersecurity incident involving the MOVEit file transfer tool. A software vulnerability was exploited by cybercriminals between May 28-29, 2023, allowing unauthorized access and data download from Maine agencies. The State became aware of the vulnerability on May 31, 2023. Affected data included names and government identifiers (SSN/TIN). The State engaged legal counsel and cybersecurity experts, patched the vulnerability, and offered two years of credit monitoring to affected individuals.
- Maine State AGas victim2023-11-09
The State of Maine reported a breach of its external systems caused by a vulnerability in MOVEit software. The incident occurred May 28-29, 2023, and was discovered on May 31, 2023. The breach affected 1,324,118 individuals nationwide, including 534,194 Maine residents. Compromised data included names and driver's license numbers. Notification was provided via substitute notice on November 9, 2023, with two years of identity protection services offered.
Supply-chain cascadesreviewed and confirmed
- State of Maine’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).