Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICCREDENTIALSLowContained
Delta Dental of Virginia
bd_77514f3f8810054e · schema v1 · pii pii-v1
Full breach record for Delta Dental of Virginia →Delta Dental of Virginia notified South Carolina AG of a phishing incident affecting one email account. Unauthorized access occurred between March 21 and April 23, 2025. Personal information (PII) was potentially accessed. No evidence of misuse. DDVA engaged forensic experts, enhanced security, and offered TransUnion identity protection services.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_258b7419633efa29HHS OCRfiled 2025-11-21Verified
- bd_33adf66631ec6cffTexas State AGfiled 2025-11-21Verified
- bd_63884c8a32550403California State AGfiled 2025-11-21Verified
- bd_6c4632d1958d0b22Vermont State AGfiled 2025-11-21Verified
Show 3 more filings ↓Show fewer ↑
- bd_a1166220222f2703New Hampshire State AGfiled 2025-11-21Verified
- bd_b83003f69cbe723dIndiana State AGfiled 2025-11-21Verified
- bd_bf99bf0f3544346bMaine State AGfiled 2025-11-21Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20Delta%20Dental%20of%20Virginia.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2025
- Raw hash
- 07bd4447b61de36bc2b583b90a4b90d016f7132aebed3ace6d706dd73b49dd72
Reporting entity
- Name
- Delta Dental of Virginianorm: delta dental of virginia
Victim entity
- Name
- Delta Dental of Virginianorm: delta dental of virginia
Incident
- Discovered
- Apr 23, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.