HackingVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsIDENTITY_BASICLowContained
GRAPHIC PACKAGING INTERNATIONAL, LLC
bd_6a7f1564e73ac67c · schema v1 · pii pii-v1
Full breach record for GRAPHIC PACKAGING INTERNATIONAL, LLC →Welltok, Inc., a wellness program provider for Graphic Packaging International, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. The incident was discovered on July 26, 2023. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and is offering credit monitoring to affected individuals. The breach affects residents of California and Rhode Island, among others.
California clockDiscovered Jul 26, 2023 → Notified Nov 21, 2023118d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_121af29fed1045f0Vermont State AGfiled 2023-11-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576987
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- abd3bbe675d7118cd41dbc7c2bd4298133f2cd5bf56729018e4fa7a9a585d613
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- GRAPHIC PACKAGING INTERNATIONAL, LLCnorm: graphic packaging
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- —
- Notification sent
- Nov 21, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Welltok, Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- CA 60-day late · 118d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 26, 2023→ Notified: Nov 21, 2023118d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.