Supply chain
β Supply Chain
Oregon Driver & Motor Vehicle Services Third-Party Breach (June 2023)
Primary Source βIncident Details
Millions of Oregon, Louisiana state IDs stolen in MOVEit breach. Louisiana and Oregon warn that millions of driver’s licenses were exposed in a data breach after a ransomware gang hacked their MOVEit Transfer security file transfer systems to steal stored data. These attacks were conducted by the Clop ransomware operation , which began worldwide hacks of MOVEit Transfer servers on May 27th using a previously unknown, zero-day vulnerability tracked as CVE-2023-34362. These attacks have led to widespread disclosures of data breaches worldwide, impacting companies, federal government agencies, and local state agencies. Third-party company: Ipswitch, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Ipswitch, Inc.
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-06-01 Breach occurred
- 2023-06-16 Publicly disclosed