Supply chain
⛓ Supply Chain
Nuance Communications Third-Party Breach (August 2023)
Primary Source ↗Incident Details
Nuance Communications Notifies 1.2M Individuals of Data Breach | TechTarget. Another incident stemming from a vulnerability in Progress Software’s MOVEit Transfer software has been reported, this time from Nuance Communications. As previously reported , organizations around the world have suffered from exploits of a vulnerability in Progress Software’s MOVEit Transfer software, allowing threat actors to gain access to databases containing sensitive information. The vulnerability has since been resolved, but breach notifications have continued to roll in. Nuance explained that as soon as it learned of the incident on May 31, 2023, it launched an investigation and reached out to law enforcement authorities. The investigation determined that some individuals’ personal information was subject to unauthorized access. The access was limited to the MOVEit Transfer application and did not impact Nuance systems. Third-party company: Ipswitch, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Ipswitch, Inc.
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2023-08-01 Breach occurred
- 2023-09-25 Publicly disclosed