Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICCREDENTIALSLowContained
Delta Dental of Virginia
bd_6c4632d1958d0b22 · schema v1 · pii pii-v1
Full breach record for Delta Dental of Virginia →Delta Dental of Virginia notified consumers of a data breach involving unauthorized access to an email account. The incident occurred between March 21, 2025, and April 23, 2025, potentially exposing personal information. DDVA engaged cybersecurity experts, enhanced security measures, and offered complimentary identity protection services through TransUnion.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_258b7419633efa29HHS OCRfiled 2025-11-21Verified
- bd_33adf66631ec6cffTexas State AGfiled 2025-11-21Verified
- bd_63884c8a32550403California State AGfiled 2025-11-21Verified
- bd_77514f3f8810054eSouth Carolina State AGfiled 2025-11-21Verified
Show 3 more filings ↓Show fewer ↑
- bd_a1166220222f2703New Hampshire State AGfiled 2025-11-21Verified
- bd_b83003f69cbe723dIndiana State AGfiled 2025-11-21Verified
- bd_bf99bf0f3544346bMaine State AGfiled 2025-11-21Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-21-delta-dental-virginia-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2025
- Raw hash
- 51e9618ebb1435bf526e21f210d4d51945ea028da0f857b805aeba4cc6d84f1c
Reporting entity
- Name
- Delta Dental of Virginianorm: delta dental of virginia
Victim entity
- Name
- Delta Dental of Virginianorm: delta dental of virginia
Incident
- Discovered
- Apr 23, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.