HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIHighContained
Blue Cross and Blue Shield of Massachusetts, Inc.
bd_249d2927c5e04cd8 · schema v1 · pii pii-v1
Full breach record for Blue Cross and Blue Shield of Massachusetts, Inc. →Cierant Corporation, a distributed marketing software vendor for Blue Cross and Blue Shield of Massachusetts, disclosed a data security event involving a vulnerability in the third-party file transfer tool Cleo VLTrader. An unauthorized actor exploited this vulnerability to gain limited access to Cierant systems, potentially acquiring files containing personal information of approximately 1,422 Rhode Island residents. The incident was discovered on December 10, 2024. Cierant ceased use of the tool, rotated passwords, and is offering credit monitoring.
California clockDiscovered Dec 10, 2024 → Notified Jul 3, 2025205d ✗ CA 60-day late30 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,422 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605063
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2025
- Raw hash
- c89c176f20ee7c0c039a3d4bb3f8576677e2e404ffc6e92d237434b7a3f52ce0
Reporting entity
- Name
- Cierantnorm: cierant
- Domain
- cierant.com
Victim entity
- Name
- Blue Cross and Blue Shield of Massachusetts, Inc.norm: blue cross and blue shield of massachusetts
Incident
- Discovered
- Dec 10, 2024
- Materiality determined
- —
- Notification sent
- Jul 3, 2025
- Affected individuals
- 1,422
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Reported the event to federal law enforcementNotifying relevant regulators
- Third party
- via Cleo
- Initial access
- supply_chain
Compliance
- Time to disclose
- 30 weeks(209 days from discovery to filing)
- Compliance flags
- CA 60-day late · 205d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 10, 2024→ Notified: Jul 3, 2025205d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.