Clustered 4 filings across 4 jurisdictions · filing window Aug 25, 2023 → Aug 26, 2023. View entity profile → Other incidents for this victim →
incident inc_2574c821e07e4c9e · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
PII · Identity (basic)
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
DE HI NH VT
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 27, 2023 → May 31, 2023
When the intrusion reportedly occurred, per the linked filings
May 30, 2023
Reported by VERMONT AG, DELAWARE AG, NEW HAMPSHIRE AG, HAWAII AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Maximus Health Services, Inc. notified consumers of a data breach involving Progress Software's MOVEit Transfer application. An unauthorized party accessed files between May 27-31, 2023, exploiting a vulnerability in the third-party software. Personal information was accessed. Maximus engaged forensic experts, took systems offline, and is offering two years of credit monitoring.
Maximus Health Services, Inc. disclosed a security incident involving the MOVEit Transfer vulnerability (Zero Day). Unauthorized access occurred between May 27-31, 2023, resulting in the exfiltration of personal information. Maximus detected the activity on May 30, 2023, took the system offline, and offered two years of credit monitoring. The incident involved a third-party software vulnerability exploited by an external actor.
Maximus, Inc. notified the New Hampshire Attorney General of a data security incident involving its MOVEit Transfer environment. An unauthorized party exploited a critical zero-day vulnerability in the third-party software (Progress Software) between May 27 and May 31, 2023, to exfiltrate files containing personal information of at least 6,376 New Hampshire residents. Maximus detected the activity on May 30, 2023, took the system offline, and began notifying residents on August 24, 2023. Remediation included credit monitoring via Experian and cooperation with the FBI.
Affected (this filing): 6,376
Maximus Health Services, Inc. notified Hawaii AG of a security incident involving the MOVEit Transfer vulnerability (Progress Software). Unauthorized access occurred May 27-31, 2023, leading to exfiltration of personal information. Maximus took the environment offline, applied vendor patches, and offered 2 years of credit monitoring. No specific count of affected individuals was provided in this filing.