HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedZero-DayPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Delta Dental
bd_84d913a18ea5d62d · schema v1 · pii pii-v1
Full breach record for Delta Dental →Delta Dental of California and affiliates experienced a data security incident involving the MOVEit Transfer software from Progress Software. Unauthorized actors exploited a previously unknown vulnerability in the software, accessing and acquiring data between May 27 and May 30, 2023. The company discovered the incident on June 1, 2023. Affected data includes personal and health information. The company engaged forensic experts, notified law enforcement, and is offering 24 months of identity monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_9e88312a77fdbd76New Hampshire State AGfiled 2024-01-24(7d gap)Verified
- bd_f9dd9d8c0025c2d4Vermont State AGfiled 2024-02-09(9d gap)Verified
- bd_ed716715756a4072California State AGfiled 2024-03-14(43d gap)Verified
- bd_b7d1eba67d9b0325California State AGfiled 2023-12-14(48d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-580275
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 31, 2024
- Raw hash
- 160d9bec23a0f3896c969e5e683941f8acbd420d10ef825fdbe312911d64b4e8
Reporting entity
- Name
- GEICO Corporationnorm: geico
Victim entity
- Name
- Delta Dentalnorm: delta dental
- Domain
- www1.deltadentalins.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 35 weeks(244 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.