MalwareRansomwareData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Delaware Life
bd_732e01ca4d2b557b · schema v1 · pii pii-v1
Full breach record for Delaware Life →Delaware Life Insurance Company experienced a ransomware attack on its IT infrastructure. The company detected the malware on February 9, 2023, though the breach date listed in the state filing is November 30, 2022. An unauthorized actor accessed and acquired files containing personal information, including names, addresses, dates of birth, and Social Security numbers of agents and policyholders. The company engaged forensic experts, notified the FBI and regulators, and is offering 24 months of identity theft protection services to affected individuals.
California clockDiscovered Feb 9, 2023 → Notified Nov 21, 2023285d ✗ CA 60-day late41 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (3)
- bd_ce46a894d90e5d33Leak Siteransomhousefiled 2023-03-11(254d gap)Verified by operator
- bd_02c5d900e9ad217aLeak Sitelockbit_3filed 2023-02-24(269d gap)Verified
- bd_e4c569822739f3c3Leak Sitedispossessorfiled 2023-02-12(281d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_607f6cf63facb9d5Washington State AGfiled 2023-11-21Verified by operator
- bd_9f6be2f093ceaca8Montana State AGfiled 2023-11-21Verified by operator
- bd_df97c5745d49d9dcOregon State AGfiled 2023-11-21Verified by operator
- bd_1021de845df9f4c5Washington State AGfiled 2023-09-06(76d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 116d gap
- bd_9561e2ebdb17cf00California State AGfiled 2023-07-28(116d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576840
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2023
- Raw hash
- 3d7472966a76e5f28d0faa878b37773d82be48c0e48fb2f61a0b9a926ec99697
Reporting entity
- Name
- Delaware Lifenorm: delaware life
- Domain
- delawarelife.com
Victim entity
- Name
- Delaware Lifenorm: delaware life
- Domain
- delawarelife.com
Incident
- Discovered
- Feb 9, 2023
- Materiality determined
- —
- Notification sent
- Nov 21, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Alerted appropriate regulatory authoritiesAlerted the Federal Bureau of Investigation
Compliance
- Time to disclose
- 41 weeks(285 days from discovery to filing)
- Compliance flags
- CA 60-day late · 285d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 9, 2023→ Notified: Nov 21, 2023285d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.