Desk live·
ForensicPost
Breaches/Healthcare/File 23-0728

Maximus Says the MOVEit Flaw Reached Health Data for up to 11 Million People

This is what the MOVEit campaign looked like at one downstream organisation. A government services contractor, a set of Medicare beneficiaries who had never heard of it, and a figure that exists because a notification regime required one.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetMaximus
ActorCl0p
S. Rosler11 min readConfidence: high2 sources reviewed

Maximus, a contractor providing government services in the United States, was among the organisations reached through the MOVEit Transfer vulnerability filed at 23-0601. It reported that personal information and protected health information for between eight and eleven million individuals may have been accessed.

Reported exposed fields include names, contact details, social security numbers, healthcare provider and prescription information, and health insurance claims. The company recorded $15 million of expenses for the quarter to 30 June 2023 in relation to the breach.

Why This File Carries A Number And The Campaign File Does Not

The MOVEit file at 23-0601 deliberately records no victim total. The circulating totals for that campaign are aggregations of leak-site listings and notification filings, assembled by researchers, and this desk does not treat them as a measurement.

This file carries a figure because a named organisation reported one against a mandatory register. That is the distinction the corpus keeps insisting on, and it is worth stating plainly: the campaign is unmeasurable and its individual victims are not.

A Contractor Nobody Chose

The people whose health data this was were Medicare beneficiaries. Their relationship was with a government programme, not with a listed services company, and the exposure travelled a path they had no visibility of and no ability to refuse.

The corpus files this at 26-0731 for Conduent, at 23-0331 for Capita and at 26-0628 for a state licensing vendor. Public-sector outsourcing produces populations who cannot exercise any of the choices that consumer privacy law assumes they have.

Social Security Numbers Change The Grade

Unlike the HCA exposure at 23-0710, this one includes social security numbers and clinical detail. That combination is the reason for the severity here: it supports both identity fraud and the kind of targeting that health information enables.

How we reported this

Built on contemporaneous reporting of Maximus’s disclosure and of the figures it reported. The range of eight to eleven million is the company’s own, reported as a range because its review was incomplete; this file carries the range rather than picking an end of it. The $15 million expense figure is the company’s for a stated quarter and is not a total cost. The attribution of the underlying campaign to Cl0p rests on the CISA/FBI advisory cited at 23-0601. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Up to 11 Million Health Records Compromised in Cyberattack on Government ContractorHIPAA Journal
  2. US government contractor says MOVEit hackers accessed health data of at least 8 million individualsTechCrunch
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary