HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
UnitedHealthcare Student Resources
bd_928c75808eb60493 · schema v1 · pii pii-v1
Full breach record for UnitedHealthcare Student Resources →UnitedHealthcare Student Resources (UHSR) disclosed a breach involving the MOVEit Transfer software. UHSR discovered suspicious activity on June 1, 2023, confirming exploitation of a zero-day vulnerability in Progress Software's MOVEit software. The incident affected member data including names, SSNs, DOBs, and claim information. UHSR took the server offline, applied patches, blocked traffic, and notified law enforcement. Affected individuals were offered two years of identity theft protection via NortonLifeLock.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_165616c6e14292acDelaware State AGfiled 2023-07-21Candidate
- bd_48ebed8cd0423105Oregon State AGfiled 2023-07-21Candidate
- bd_8822f16abda9f159California State AGfiled 2023-07-21Verified
- bd_a943750d0cfa2722Washington State AGfiled 2023-07-26(5d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/MOVEiT-SR-Sample-Member-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2023
- Raw hash
- 046b0c9f3551600ac5531e277dbea465216076c3cf96cb4d0016abf72020dcbc
Reporting entity
- Name
- UnitedHealthcare Privacy Officenorm: unitedhealthcare privacy office
Victim entity
- Name
- UnitedHealthcare Student Resourcesnorm: unitedhealthcare student resources
- Domain
- myaccount.uhcsr.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.