Confirmed breach. Intrusion May 28, 2023, discovered May 31, 2023 — the first regulatory filing landed 303 days later (flagged late). 1,000 individuals reported across the linked filings.
University System of Georgia, a education sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-31 and filed notice on 2024-03-29. 1,000 Washington residents were affected. 303 days elapsed between awareness and notification. 3 days to identify the breach.
Affected (this filing): 1,000
WA AG >90d
🍁Vermont State AGMost recentlinked via multistate filing link · 100%
The University System of Georgia (USG) disclosed a data breach involving its MOVEit Secure File Transfer software, purchased from Progress Software. A vulnerability in the software allowed the cybercriminal group CL0P to access files starting May 28, 2023. USG blocked the software on May 31, 2023, and updated it. Affected data included SSNs, dates of birth, bank account numbers, and tax documents. USG is offering credit monitoring via Experian.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.