DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDMediumContained

Anthem Blue Cross Blue Shield

bd_1d2bf60075702a7d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 26, 2023

Filed

Apr 3, 2024

To disclose

34 weeks

Affected

4state residents only

Confidence

66%
Full breach record for Anthem Blue Cross Blue Shield23 incidents on file

Welltok, Inc. reported a cybersecurity incident involving the MOVEit Transfer server for Anthem Blue Cross Blue Shield. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok discovered the breach on August 11, 2023, after a third-party investigation. Approximately 4 New Hampshire residents were notified on January 23, 2024. Data types included identity and government identifiers. Welltok provided credit monitoring via Experian.

Incident timeline

undetected · 57 days
discovery → filing · 36 weeks / 252 days

May 30, 2023

Begins

Jul 26, 2023

Discovered

Apr 3, 2024

Filed

vs. sector median

+22 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.