HackingVulnerability ExploitData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
DELTA DENTAL OF CALIFORNIA
bd_40e8f6904a6f52b9 · schema v1 · pii pii-v1
Full breach record for DELTA DENTAL OF CALIFORNIA →Delta Dental of California reported a data breach involving the MOVEit Transfer software vulnerability. Unauthorized actors accessed and acquired company information between May 27 and May 30, 2023. The incident impacted personal information including names, addresses, and potentially financial or government IDs. Delta Dental engaged forensic experts, patched systems, reset passwords, and notified law enforcement. Affected individuals were offered 24 months of identity monitoring via Kroll.
Vermont clock✗ VT AG >45 bday28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2c29103cacdbca1fOregon State AGfiled 2023-12-14Candidate
- bd_54f04c0719e262cfMontana State AGfiled 2023-12-14Verified
- bd_9c3c9a75bc9bb912Washington State AGfiled 2023-12-14Verified
- bd_b0392e182589e950Maine State AGfiled 2023-12-29(15d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-14-delta-dental-california-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 14, 2023
- Raw hash
- 643414f2eb157a1321e24c2dbbf9b94f6d4ff3fd82beae063504a5b45a3a431e
Reporting entity
- Name
- DELTA DENTAL OF CALIFORNIAnorm: delta dental of california
- Domain
- deltadentalca.com
Victim entity
- Name
- DELTA DENTAL OF CALIFORNIAnorm: delta dental of california
- Domain
- deltadentalca.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- Nov 27, 2023
- Notification sent
- Dec 14, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement of the incident and have been cooperating with them
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 weeks(196 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.