DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Government IDMediumContained

Blue Cross and Blue Shield of Massachusetts, Inc.

bd_154646e20b01c5db · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 10, 2024

Filed

Jul 7, 2025

To disclose

30 weeks

Affected

79state residents only

Linked

9 filings

Confidence

66%

Cierant Corporation, on behalf of Blue Cross and Blue Shield of Massachusetts, disclosed a data security event involving the third-party file transfer tool Cleo VLTrader. Cierant detected suspicious activity on December 10, 2024, and determined an unauthorized actor exploited a vulnerability in the tool to access systems and potentially acquire files. Personal information, including identity data, may have been involved. Cierant ceased use of the tool, rotated passwords, enhanced security controls, and notified law enforcement and regulators. Affected individuals are offered 12 months of credit monitoring.

Incident timeline

discovery → filing · 30 weeks / 209 days

Dec 10, 2024

Discovered

Jul 7, 2025

Filed

vs. sector median

+18 wks slower

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 6d gap

Filing propagation · 8 filings · 6 states

View merged incident ↗

Pattern: first filing Jul 1 (IL), last Jul 8 (TX) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.