November 10, 2023 at 07:00AM
The State of Maine has reported significant impact from a cyberattack on Progress Software’s MOVEit file transfer tool earlier this year. Over 2,500 organizations and 69 million individuals have been affected. The attackers accessed personal information, including names, Social Security numbers, and medical information. The Maine Department of Health and Human Services was most impacted. Maine is notifying affected individuals and providing complimentary credit monitoring and identity theft protection services.
Key takeaways from the meeting notes are as follows:
1. The State of Maine has disclosed significant impact from a cyberattack targeting Progress Software’s MOVEit file transfer tool.
2. The vulnerability exploited in the attack was an unauthenticated SQL injection issue, described as critical.
3. A ransomware gang accessed data transferred through the MOVEit software.
4. Over 2,500 organizations and 69 million individuals have been affected by the MOVEit hack, according to cybersecurity firm Emsisoft.
5. 1.3 million of the affected individuals are Maine residents, as confirmed by the State of Maine.
6. The attackers accessed personal information such as names, dates of birth, Social Security numbers, driver’s license/state identification numbers, and taxpayer identification numbers. In some cases, medical and health insurance information was also compromised.
7. The State of Maine holds information about individuals for various reasons and engages in data sharing agreements with other organizations.
8. The attackers accessed and downloaded files belonging to certain agencies in the State of Maine through the MOVEit server.
9. The Maine Department of Health and Human Services was the most impacted, followed by the Maine Department of Education.
10. The State of Maine took immediate steps to secure its information, including blocking internet access to and from the MOVEit server.
11. Impacted individuals are being notified by Maine and provided with complimentary credit monitoring and identity theft protection services.
12. Other entities, such as US schools and a Colorado health agency, have also been impacted by the MOVEit hack.
13. A ransomware gang has allegedly leaked data stolen from Canadian hospitals.
Please let me know if you need any additional information.