HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
AlohaCare
bd_5def3fef6b1cfeb3 · schema v1 · pii pii-v1
Full breach record for AlohaCare →AlohaCare notified the California Attorney General of a data breach involving a zero-day vulnerability in the MOVEit file transfer tool. On May 31, 2023, the company learned it was part of the incident. The investigation concluded on October 17, 2023. Affected data may include names, addresses, dates of birth, and Social Security numbers. AlohaCare engaged cybersecurity experts and offered 12 months of free credit monitoring.
California clockDiscovered May 31, 2023 → Notified Nov 3, 2023156d ✗ CA 60-day late22 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_267bf6a743ba7a14Leak Sitecl0pfiled 2023-07-26(100d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_35d7cd006030565aVermont State AGfiled 2023-11-03Verified
- bd_51b508a9a3d16f90Hawaii State AGfiled 2023-11-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576076
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2023
- Raw hash
- 66675ab8701a84fa9ac5d550f894136377ddbeb7edcf117ef03ce32dd20f1660
Reporting entity
- Name
- AlohaCarenorm: alohacare
- Domain
- alohacare.org
Victim entity
- Name
- AlohaCarenorm: alohacare
- Domain
- alohacare.org
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Nov 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Progress Software (MOVEit)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 weeks(156 days from discovery to filing)
- Compliance flags
- CA 60-day late · 156dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Nov 3, 2023156d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.