Hillsborough County notified more than 70,000 people after MOVEit breach

Organization
Hillsborough County, Florida
Exploit
Supply Chain Attack
Industry
Local Government

Hillsborough County, Florida began notifying more than 70,000 people in July 2023 that their personal and health information may have been exposed through MOVEit Transfer, the file transfer software compromised in a global exploitation campaign.

County cybersecurity staff were alerted to the MOVEit vulnerability on June 1, 2023 and installed security patches, then continued adding protective measures over the following two weeks. On June 18 the county determined that its own files could have been caught up in the incident.

The files at issue belonged to the county's Healthcare Services and Aging Services departments. According to the county, they could have contained first and last names, Social Security numbers, dates of birth, home addresses, medical conditions and diagnoses, and disability codes. Employees of Aging Services vendors were also potentially affected, and the county said it notified twelve vendors so they could alert their own staff.

Hillsborough County said it had not been specifically targeted and was affected as one of many organizations that used the software. It mailed notification letters to 70,636 people, opened a toll-free helpline for questions, and advised recipients to place fraud alerts with Equifax, Experian and TransUnion. Neither the county nor local reporting identified a group as responsible for the county's portion of the campaign.

Sources