Clustered 7 filings across 6 jurisdictions · filing window Nov 9, 2023 → Nov 27, 2023. View entity profile → Other incidents for this victim →
incident inc_4a451e117cbb4b73 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA ME MT OR VT WA
HHS OCR · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
May 28, 2023
When the intrusion reportedly occurred, per the linked filings
May 31, 2023
Reported by MAINE AG, VERMONT AG, WASHINGTON AG, CALIFORNIA AG, OREGON AG filings
The State of Maine reported to HHS on 2023-11-16 a Hacking/IT Incident affecting 376,504 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names, DOB, SSN, diagnoses, and claims. The CE provided complimentary credit monitoring and implemented additional safeguards.
Affected (this filing): 376,504
The State of Maine experienced a data breach involving the MOVEit file transfer tool owned by Progress Software. Cybercriminals exploited a software vulnerability to access and download files from certain state agencies between May 28 and May 29, 2023. The State became aware of the incident on May 31, 2023. Affected data may include names and Social Security numbers or taxpayer identification numbers. The State blocked internet access to the server, patched the vulnerability, engaged legal and cybersecurity experts, and offered two years of credit monitoring to affected individuals.
State of Maine reported a data breach to the Oregon Attorney General. The breach was reported on 2023-11-27. The breach occurred during 5/28/2023 - 5/29/2023. The breach was discovered on 5/31/2023. 1,324,118 individuals were affected. Notice was sent on 11/9/2023.
Affected (this filing): 1,324,118
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
The State of Maine notified consumers of a data breach involving its MOVEit file transfer tool, owned by Progress Software. Cybercriminals exploited a vulnerability between May 28-29, 2023, to access and download files from certain state agencies. Affected data included names and government identifiers (SSN/TIN). The State engaged legal counsel and cybersecurity experts, patched the vulnerability, and offered two years of credit monitoring to affected individuals.
State of Maine reported a data breach to the Montana Attorney General. The breach was reported on 2023-11-09. The breach occurred from 5/28/2023 to 5/29/2023. 232 Montana residents were affected.
Affected (this filing): 232
The State of Maine reported a breach of its external systems caused by a vulnerability in MOVEit software. The incident occurred May 28-29, 2023, and was discovered on May 31, 2023. The breach affected 1,324,118 individuals nationwide, including 534,194 Maine residents. Compromised data included names and driver's license numbers. Notification was provided via substitute notice on November 9, 2023, with two years of identity protection services offered.
Affected (this filing): 1,324,118
State of Maine, a government sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-31 and filed notice on 2023-11-13. 2,606 Washington residents were affected. 166 days elapsed between awareness and notification. 3 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 2,606