HackingStolen CredentialsData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIPIIMediumContained
HEALTHEQUITY, INC.
bd_78b071a1c9f6bb51 · schema v1 · pii pii-v1
Full breach record for HEALTHEQUITY, INC. →HealthEquity, Inc. notified consumers of a data breach where a third-party vendor's compromised accounts led to unauthorized access to an unstructured data repository. The incident, discovered on March 25, 2024, exposed PII including names, addresses, SSNs, and financial account info. HealthEquity engaged forensic experts, disabled compromised accounts, and offered two years of credit monitoring.
Vermont clock✗ VT AG >45 bday18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 407 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_af6fccca3bd7dd5aCalifornia State AGfiled 2024-07-26Verified
- bd_5de1919bf0e7e946Indiana State AGfiled 2024-07-29(3d gap)Verified
- bd_c6e8a0e9ea2fbb67HHS OCRfiled 2024-08-09(14d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-07-26-healthequity-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2024
- Raw hash
- 44fe7c5389b729f7285727db05f1a9ce370daacfb36d3a3be9975678460de12d
Reporting entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Victim entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Incident
- Discovered
- Mar 25, 2024
- Materiality determined
- —
- Notification sent
- Jul 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 18 weeks(123 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.