HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIALMediumContained
UnitedHealthcare Student Resources
bd_8822f16abda9f159 · schema v1 · pii pii-v1
Full breach record for UnitedHealthcare Student Resources →UnitedHealthcare Student Resources disclosed a data breach involving the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer product. The incident occurred on May 27, 2023, and was discovered on June 1, 2023. Affected data included names, SSNs, health information, and financial claim details. The company took the server offline, applied patches, and offered identity theft protection.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_165616c6e14292acDelaware State AGfiled 2023-07-21Candidate
- bd_48ebed8cd0423105Oregon State AGfiled 2023-07-21Candidate
- bd_928c75808eb60493Delaware State AGfiled 2023-07-21Verified
- bd_a943750d0cfa2722Washington State AGfiled 2023-07-26(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570667
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2023
- Raw hash
- 3401ba6ef5527d903297be1aede78149de3cfec95e9c5cdd2cac19fe029a9c6d
Reporting entity
- Name
- UnitedHealthcare Student Resourcesnorm: unitedhealthcare student resources
- Domain
- myaccount.uhcsr.com
Victim entity
- Name
- UnitedHealthcare Student Resourcesnorm: unitedhealthcare student resources
- Domain
- myaccount.uhcsr.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.