Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Up to 11 Million People Hit by MOVEit Hack at Government Services Firm Maximus

Maximus Inc says that the personal information of 8 to 11 million individuals was stolen in the MOVEit cyberattack.

Government services provider Maximus this week revealed that the personal information of up to 11 million individuals was stolen in the MOVEit cyberattack earlier this year.

Disclosed at the end of May, the attack involved the exploitation of a zero-day vulnerability in the MOVEit Transfer managed file transfer (MFT) software, allowing cybercriminals to tap into the data transferred through the service.

According to cybersecurity firm Emsisoft, as of July 26, there were 513 organizations impacted by the MOVEit hack. The personal information of approximately 35 million individuals has been stolen in the malicious campaign.

In a Form 8-K filing with the US Securities and Exchange Commission (SEC) on Wednesday, Maximus confirmed that it is one of the companies impacted by the attack.

“Maximus, Inc. uses MOVEit for internal and external file sharing purposes, including to share data with government customers pertaining to individuals who participate in various government programs,” the company said.

According to Maximus, the attackers stole files containing the personal information and protected health information, including Social Security numbers, “of at least 8 to 11 million individuals”.

The company also noted that the investigation into the incident is ongoing and that it cannot predict the total number of impacted individuals, but said that it was planning on providing notifications to those affected.

“At present, there is no indication that the incident has had any impact on the internal information technology systems of the company or its customers beyond the MOVEit environment, and there has been no material interruption to the company’s business operations due to the incident,” Maximus said.

Advertisement. Scroll to continue reading.

However, the company believes that the investigation and remediation activities associated with the incident would incur expenses of “approximately $15 million for the quarter ended June 30, 2023”.

Headquartered in Reston, Virginia, Maximus works with government agencies in the US, Australia, Canada, and the UK, managing and administering government-sponsored health and human services programs. The company has more than 34,000 employees.

Related: MOVEit Hack Could Earn Cybercriminals $100M as Number of Confirmed Victims Grows

Related: Cosmetics Giant Estée Lauder Targeted by Two Ransomware Groups

Related: Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Data Breaches

Delta Dental of California says over 6.9 million individuals were impacted by a data breach caused by the MOVEit hack.

Data Breaches

Sony shares information on the impact of two recent unrelated hacker attacks carried out by known ransomware groups. 

Data Breaches

AT&T is notifying millions of wireless customers that their CPNI was compromised in a data breach at a third-party vendor.

Data Breaches

A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy.