Clustered 8 filings across 6 jurisdictions · filing window Dec 29, 2023 → Feb 2, 2024. View entity profile → Other incidents for this victim →
incident inc_0e1d2a44e4714a18 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA IN ME MT NH VT
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
8 filings across 6 jurisdictions · Dec 29, 2023 – Feb 2, 2024 · 2 milestones
May 31, 2023
When the intrusion reportedly occurred, per the linked filings
Nov 30, 2023
Reported by MAINE AG, VERMONT AG, CALIFORNIA AG filings
Amwins Group, Inc. notified residents of multiple states, including New Hampshire and Rhode Island, of a data incident involving its third-party vendor, Paycor. Unauthorized access to Amwins' network did not occur. The incident involved potential exposure of personal information of employees and individuals. Amwins provided credit monitoring services through Experian and enhanced its third-party vendor privacy policies.
Amwins Group, Inc. notified consumers of a data breach involving its HR vendor Paycor, which used Progress MOVEit Transfer. Vulnerabilities exploited in May/June 2023 allowed unauthorized access. Affected data includes names and government IDs. Amwins offered Experian credit monitoring. No direct access to Amwins' network occurred.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Amwins Group, Inc. notified New Hampshire residents of a data incident involving third-party vendor Paycor. No unauthorized access to Amwins' network occurred. The incident potentially exposed personal information of 62 NH residents. Amwins provided credit monitoring via Experian and guidance on identity theft protection.
Affected (this filing): 62
Amwins Group, Inc. notified consumers of a data breach involving its payroll vendor Paycor, which used Progress MOVEit Transfer. Attackers exploited vulnerabilities in MOVEit to access servers containing employee personal information, including names and government IDs. Amwins offered credit monitoring via Experian. The incident is part of the broader MOVEit supply chain compromise.
Amwins Group, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-31 and was reported on 2023-12-29. 44 Indiana residents were affected. 7,224 individuals affected in total.
Affected (this filing): 7,224
Amwins Group, Inc. notified employees of a data security event involving its HR vendor, Paycor, Inc., and its file transfer provider, Progress MOVEit. An unauthorized actor exploited previously unknown vulnerabilities in MOVEit Transfer to access servers used by Paycor. Amwins received notification on November 30, 2023. The incident affected employee personal information, including names and other data. Amwins conducted an internal review and is offering credit monitoring services. No unauthorized access to Amwins' own network occurred.
Amwins Group, Inc. reported an external system breach that occurred on May 31, 2023, and was discovered on November 30, 2023. The breach affected 7,224 individuals, compromising names and Social Security numbers. Affected individuals were notified on December 29, 2023, and offered 12 months of credit monitoring and identity restoration services from Experian.
Affected (this filing): 7,224
Amwins Group, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-12-29. The breach occurred from 5/30/2023 to 5/31/2023. 1 Montana residents were affected.
Affected (this filing): 1