HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICHEALTH_BASICLowContained
Welltok
bd_7a0d595bd5e1a3d3 · schema v1 · pii pii-v1
Full breach record for Welltok →Welltok, Inc. disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names, member IDs, dates of birth, addresses, phone numbers, and medication information. The company was alerted to the compromise on July 26, 2023, and confirmed the breach on August 11, 2023. Affected individuals include customers of Prime Therapeutics and Stanford Health Care. Welltok is offering credit monitoring and identity restoration services.
California clockDiscovered Jul 26, 2023 → Notified Nov 18, 2023115d ✗ CA 60-day late16 weeks discovery → filing
This filing is one of 17 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_e378dc71f9be8ac0Maine State AGfiled 2023-12-05(18d gap)Verified by operator
- bd_f5d34ac976e2a29fNew Hampshire State AGfiled 2023-12-05(18d gap)Verified
- bd_063b1deb8c7a2bffMaine State AGfiled 2023-12-15(28d gap)Verified by operator
- bd_69d99adc86ef4dcfVermont State AGfiled 2023-12-15(28d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 35d gap
- bd_b765e398c9850ca1California State AGfiled 2023-12-15(28d gap)Verified
- bd_e5a605be617ae396New Hampshire State AGfiled 2023-12-15(28d gap)Verified
- bd_0328ea1fdab9c459Maine State AGfiled 2023-12-22(35d gap)Verified by operator
- bd_5e4b7107bd1176deCalifornia State AGfiled 2023-12-22(35d gap)Verified
- bd_8ca9e17ac4dfbe9bVermont State AGfiled 2023-12-22(35d gap)Verified
- bd_db6e6d3e58b51e90New Hampshire State AGfiled 2023-12-22(35d gap)Verified
Showing first 10 of 16 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576748
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2023
- Raw hash
- e4d30ed4523ace42284909c2293863f5e7a63dde819cdf65b3163a507e71737f
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- —
- Notification sent
- Nov 18, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- CA 60-day late · 115d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 26, 2023→ Notified: Nov 18, 2023115d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.