HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICHEALTH_BASICLowContained
Express Scripts, Inc.
bd_692ca0e73337b6e0 · schema v1 · pii pii-v1
Full breach record for Express Scripts, Inc. →Express Scripts notified members of unauthorized access to their Express Scripts mobile application accounts between April 30 and May 3, 2022. A bad actor used credentials obtained from a separate breach (credential stuffing) to access accounts. Affected data included prescription history, medication names, and pharmacy information. Express Scripts locked affected accounts and required password resets. Members were offered free identity theft protection via Equifax.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_c05ac047f6d07013Montana State AGfiled 2022-06-01(2d gap)Verified
- bd_ced8b9f8cc34a516California State AGfiled 2022-06-03(4d gap)Candidate
- bd_8ae6086e173bb504Montana State AGfiled 2022-07-10(41d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/06/ESI-Mobile-App-Cred-Stuff-Member-Notification-Template-220-FINAL-1.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 30, 2022
- Raw hash
- 8f0c4b0f2a5052179352f5c6797228403fe3970450862593eb17807f3e0d7db2
Reporting entity
- Name
- Express Scripts, Inc.norm: express scripts
- Domain
- express-scripts.com
Victim entity
- Name
- Express Scripts, Inc.norm: express scripts
- Domain
- express-scripts.com
Incident
- Discovered
- May 1, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.