Maximus says MOVEit hack exposed data on up to 11 million people
- Organization
- Maximus Inc.
- Exploit
- Supply Chain Attack
- Industry
- Government Services
Maximus Inc., a contractor that administers health and human services programs for government agencies in the United States, Australia, Canada and the United Kingdom, disclosed in a Form 8-K filed with the U.S. Securities and Exchange Commission on July 26, 2023 that it had been caught up in the MOVEit Transfer campaign.
The company said it learned in late May 2023 that attackers had exploited a zero day flaw in the Progress Software file transfer product, tracked as CVE-2023-34362, to reach files it moved through the application. Its review indicated the attackers obtained personal information and protected health information, including Social Security numbers, belonging to at least 8 million and potentially as many as 11 million individuals.
Maximus said it isolated the MOVEit environment from its corporate network and found no indication that the intrusion reached its other internal systems. It estimated investigation and remediation expenses of roughly $15 million for the quarter ended June 30, 2023, and said individual notifications would follow as the review continued.
The Clop extortion group, which ran the MOVEit campaign, added Maximus to its leak site among a batch of new victims and claimed to hold about 169 gigabytes of data taken from the company's server, though it had not published the files at the time of reporting. The victim range made Maximus one of the largest single casualties of the campaign to that point.