ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

California-based MESVision says MOVEit Transfer breach impacted close to 350k patients

California based eye care provider MESVision said the information of close to 350,000 patients was compromised after cyber criminals exploited a zero-day vulnerability in Progress Software’s MOVEit Transfer web application.Founded in 1976, MESVision provides vision care plans to thousands of employer groups and millions of plan members across the United States for leading health care organisations, insurance carriers, and self-funded employer groups.In a data breach notification filed with the Attorney General’s office of Maine, Medical Eye Services (MESVision) said that it used Progress Software’s MOVEit Transfer web application to send and receive files securely and was impacted after cyber criminals exploited a zero-day vulnerability in the application earlier this year.After being notified by Progress Software, the manufacturer of MOVEit software, MESVision immediately took the server offline and launched an internal investigation with assistance from third party cyber security experts to understand the scope of the incident.“It was determined that the unauthorised individual exfiltrated information from the server on May 28, 2023, and May 31, 2023,” the notice read.The affected data belonged to patients who enrolled in vision benefit plans managed by MESVision. The compromised data included the names and other personal identifiers along with Social Security Numbers. The filing with the regulator also confirms that at least 346,828 individuals were impacted by the incident.“MESVision has rebuilt the MOVEit system in accordance with vendor requirements and with our gold standard build requirements. Before reactivating the system, we took a number of technical measures to validate the security protections put in place,” the healthcare provider said.MESVision has urged all affected individuals to remain vigilant and keep an eye out for any suspicious activities in their credit report. It is also providing a year of complimentary identity monitoring services, including credit monitoring, fraud consultation, and identity theft restoration via Kroll to all affected individuals.More than 2,390 organisations worldwide have so far suffered significant data breaches as a result of the Clop ransomware group exploiting vulnerabilities in Progress Software’s MOVEit Transfer web application.According to German cybersecurity research firm KonBriefing, as of November 16, at least 2,393 organisations worldwide have suffered security incidents resulting from the exploitation of the software and up to 73.8 million individuals have been impacted so far.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543