HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Welltok
bd_5e4b7107bd1176de · schema v1 · pii pii-v1
Full breach record for Welltok →Welltok, Inc. disclosed that an unknown actor exploited a zero-day vulnerability in Progress Software's MOVEit Transfer tool between May 30-31, 2023, exfiltrating data including names, addresses, phone numbers, Member IDs, DOB/Age, Medicaid IDs, and plan types. Welltok learned of the potential impact on July 26, 2023, and confirmed the breach on August 11, 2023. The company engaged third-party cybersecurity specialists and is offering 24 months of credit monitoring via Experian.
California clockDiscovered Jul 26, 2023 → Notified Dec 22, 2023149d ✗ CA 60-day late21 weeks discovery → filing
This filing is one of 17 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_0328ea1fdab9c459Maine State AGfiled 2023-12-22Verified by operator
- bd_8ca9e17ac4dfbe9bVermont State AGfiled 2023-12-22Verified
- bd_db6e6d3e58b51e90New Hampshire State AGfiled 2023-12-22Verified
- bd_063b1deb8c7a2bffMaine State AGfiled 2023-12-15(7d gap)Verified by operator
Show 6 more filings ↓Show fewer ↑up to 29d gap
- bd_69d99adc86ef4dcfVermont State AGfiled 2023-12-15(7d gap)Verified
- bd_b765e398c9850ca1California State AGfiled 2023-12-15(7d gap)Verified
- bd_e5a605be617ae396New Hampshire State AGfiled 2023-12-15(7d gap)Verified
- bd_e378dc71f9be8ac0Maine State AGfiled 2023-12-05(17d gap)Verified by operator
- bd_f5d34ac976e2a29fNew Hampshire State AGfiled 2023-12-05(17d gap)Verified
- bd_f45541c4fa22d1ebMaine State AGfiled 2023-11-23(29d gap)Verified by operator
Showing first 10 of 16 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578388
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2023
- Raw hash
- 1a57b5e7543d685e1301fff1af60696d7dd78380c64657330df0187bf83d3f4c
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- —
- Notification sent
- Dec 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 21 weeks(149 days from discovery to filing)
- Compliance flags
- CA 60-day late · 149d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 26, 2023→ Notified: Dec 22, 2023149d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.