HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
AlohaCare
bd_51b508a9a3d16f90 · schema v1 · pii pii-v1
Full breach record for AlohaCare →AlohaCare notified Hawaii residents of a data security incident involving the MOVEit file transfer tool. On or around May 31, 2023, AlohaCare learned it was affected by a zero-day vulnerability in the software. The incident potentially exposed personal information including names, addresses, dates of birth, and Social Security numbers. AlohaCare engaged cybersecurity experts, concluded its investigation on October 17, 2023, and implemented additional security measures. Free credit monitoring services were offered to affected individuals.
Leak gap clock⏱ Leak >90d22 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 100 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_267bf6a743ba7a14Leak Sitecl0pfiled 2023-07-26(100d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_35d7cd006030565aVermont State AGfiled 2023-11-03Verified
- bd_5def3fef6b1cfeb3California State AGfiled 2023-11-03Verified by operator
Source provenance
- Source URL
- https://cca.hawaii.gov/wp-content/uploads/2026/05/2023-1113.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2023
- Raw hash
- 3f16d837288dbd707af5ca823141f433b96c6e9bb000e9f5bc1fdb81e23c8065
Reporting entity
- Name
- AlohaCarenorm: alohacare
- Domain
- alohacare.org
Victim entity
- Name
- AlohaCarenorm: alohacare
- Domain
- alohacare.org
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Nov 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 weeks(156 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.