Allegheny County MOVEit breach exposed data on more than 950,000 people

Organization
Allegheny County, Pennsylvania
Exploit
Hacking
Industry
Local Government

Allegheny County, Pennsylvania, which includes Pittsburgh, notified residents in late July and early August 2023 that their personal information had been exposed through the MOVEit Transfer file sharing tool.

The county said attackers accessed files on its MOVEit server on May 28 and 29, 2023, and that it was notified of the underlying vulnerability on June 1. The Clop extortion group, which government officials described as Russian speaking, ran the wider campaign against MOVEit users.

What was exposed varied by individual, depending on their dealings with county agencies. It could include names, Social Security numbers, dates of birth, driver's license or state identification numbers, taxpayer identification numbers and student identification numbers. For some people it also included medical information such as diagnosis, treatment type and admission date, health insurance information, and billing or claim information. A breach notice filed with the Maine attorney general put the number of affected people at more than 950,000.

The county opened a call center so residents could check whether they were affected and offered 24 months of identity protection through IDX to anyone whose Social Security number was involved, with an enrollment deadline of October 31, 2023.

County officials said they were not relying on the attackers' claim to have deleted government files and proceeded with notifications as a precaution.

Sources