HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICLowContained
Welltok
bd_8ca9e17ac4dfbe9b · schema v1 · pii pii-v1
Full breach record for Welltok →Welltok, Inc. notified consumers of a data breach involving its MOVEit Transfer server, a third-party tool used to manage data for OSF Healthcare. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated personal information, including names. Welltok engaged third-party cybersecurity specialists and is offering credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 17 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_0328ea1fdab9c459Maine State AGfiled 2023-12-22Verified by operator
- bd_5e4b7107bd1176deCalifornia State AGfiled 2023-12-22Verified
- bd_db6e6d3e58b51e90New Hampshire State AGfiled 2023-12-22Verified
- bd_063b1deb8c7a2bffMaine State AGfiled 2023-12-15(7d gap)Verified by operator
Show 6 more filings ↓Show fewer ↑up to 29d gap
- bd_69d99adc86ef4dcfVermont State AGfiled 2023-12-15(7d gap)Verified
- bd_b765e398c9850ca1California State AGfiled 2023-12-15(7d gap)Verified
- bd_e5a605be617ae396New Hampshire State AGfiled 2023-12-15(7d gap)Verified
- bd_e378dc71f9be8ac0Maine State AGfiled 2023-12-05(17d gap)Verified by operator
- bd_f5d34ac976e2a29fNew Hampshire State AGfiled 2023-12-05(17d gap)Verified
- bd_f45541c4fa22d1ebMaine State AGfiled 2023-11-23(29d gap)Verified by operator
Showing first 10 of 16 linked disclosures.
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-22-welltok-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2023
- Raw hash
- af7e39e87de9c20d2144553ea2780f82a235c4206cccad13b7fb66c218ff06ff
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Incident
- Discovered
- Aug 11, 2023
- Materiality determined
- —
- Notification sent
- Dec 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.