MalwareRansomwareCL0PData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)TargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
CareSource
bd_023953673f35b827 · schema v1 · pii pii-v1
Full breach record for CareSource →CareSource, a managed care organization, reported a breach involving its MOVEit file transfer vendor. The CL0P ransomware group exploited a vulnerability on May 31, 2023, exfiltrating data including PHI, SSNs, and member details. CareSource discovered the breach on June 27, 2023, patched the system, and engaged Kroll for forensics. 70 New Hampshire residents were affected. Notifications began August 25, 2023, offering credit monitoring.
Leak gap clock⏱ Leak >30d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 62 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_92cee760ff4463cdLeak Sitecl0pfiled 2023-06-29(62d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/caresource-20230830.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 30, 2023
- Raw hash
- 475c80bdb5a77fc93c98745ea607b1da10da87e8a91acc21958061912d855a9a
Reporting entity
- Name
- CareSourcenorm: caresource
- Domain
- caresource.com
Victim entity
- Name
- CareSourcenorm: caresource
- Domain
- caresource.com
Incident
- Discovered
- Jun 27, 2023
- Materiality determined
- —
- Notification sent
- Aug 25, 2023
- Affected individuals
- 70
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access· CL0P
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0PExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.