HackingVulnerability ExploitStolen CredentialsData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Gerber Life Insurance Company
bd_49f3137f60325c13 · schema v1 · pii pii-v1
Full breach record for Gerber Life Insurance Company →Gerber Life Insurance Company notified the California AG of a data breach involving its service provider, MESVision. An unauthorized individual exploited a vulnerability in MESVision's MOVEit server to exfiltrate personal information (including SSNs and DOBs) of vision benefit plan enrollees on May 28 and May 31, 2023. MESVision discovered the incident on August 23, 2023. The server was taken offline, and a cybersecurity firm was engaged. Affected individuals are offered credit monitoring.
California clockDiscovered Aug 23, 2023 → Notified Nov 15, 202384d ✗ CA 60-day late12 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576675
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2023
- Raw hash
- 0136eb9188cd17f8d38713a5385398fbc61d82293f3ef675c751c8553ed641a5
Reporting entity
- Name
- MESVisionnorm: mesvision
Victim entity
- Name
- Gerber Life Insurance Companynorm: gerber life insurance
- Domain
- gerberlife.com
Incident
- Discovered
- Aug 23, 2023
- Materiality determined
- —
- Notification sent
- Nov 15, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the incident to the FBI
- Third party
- via MESVision
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 23, 2023→ Notified: Nov 15, 202384d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.