Maximus, a contractor providing government services in the United States, was among the organisations reached through the MOVEit Transfer vulnerability filed at 23-0601. It reported that personal information and protected health information for between eight and eleven million individuals may have been accessed.
Reported exposed fields include names, contact details, social security numbers, healthcare provider and prescription information, and health insurance claims. The company recorded $15 million of expenses for the quarter to 30 June 2023 in relation to the breach.
Why This File Carries A Number And The Campaign File Does Not
The MOVEit file at 23-0601 deliberately records no victim total. The circulating totals for that campaign are aggregations of leak-site listings and notification filings, assembled by researchers, and this desk does not treat them as a measurement.
This file carries a figure because a named organisation reported one against a mandatory register. That is the distinction the corpus keeps insisting on, and it is worth stating plainly: the campaign is unmeasurable and its individual victims are not.
A Contractor Nobody Chose
The people whose health data this was were Medicare beneficiaries. Their relationship was with a government programme, not with a listed services company, and the exposure travelled a path they had no visibility of and no ability to refuse.
The corpus files this at 26-0731 for Conduent, at 23-0331 for Capita and at 26-0628 for a state licensing vendor. Public-sector outsourcing produces populations who cannot exercise any of the choices that consumer privacy law assumes they have.
Social Security Numbers Change The Grade
Unlike the HCA exposure at 23-0710, this one includes social security numbers and clinical detail. That combination is the reason for the severity here: it supports both identity fraud and the kind of targeting that health information enables.
Built on contemporaneous reporting of Maximus’s disclosure and of the figures it reported. The range of eight to eleven million is the company’s own, reported as a range because its review was incomplete; this file carries the range rather than picking an end of it. The $15 million expense figure is the company’s for a stated quarter and is not a total cost. The attribution of the underlying campaign to Cl0p rests on the CISA/FBI advisory cited at 23-0601. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.