HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Anthem Blue Cross Blue Shield
bd_1d2bf60075702a7d · schema v1 · pii pii-v1
Full breach record for Anthem Blue Cross Blue Shield →Welltok, Inc. reported a cybersecurity incident involving the MOVEit Transfer server for Anthem Blue Cross Blue Shield. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok discovered the breach on August 11, 2023, after a third-party investigation. Approximately 4 New Hampshire residents were notified on January 23, 2024. Data types included identity and government identifiers. Welltok provided credit monitoring via Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/welltok-20240403.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2024
- Raw hash
- 4a1b246774815a0e878e7b261d1d16da5dcb1bba655fb1cd7d37b00ba3e1c5d7
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Anthem Blue Cross Blue Shieldnorm: anthem blue cross blue shield
- Domain
- abcbs.anthem.com
Incident
- Discovered
- Aug 11, 2023
- Materiality determined
- —
- Notification sent
- Jan 23, 2024
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 34 weeks(236 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.