HackingStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryMulti-Stage ChainIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICCriticalContained
WebTPA
bd_9a8e136e8c012acf · schema v1 · pii pii-v1
Full breach record for WebTPA →WebTPA Employer Services, LLC reported a data breach to the South Carolina Department of Consumer Affairs on July 22, 2024, covering a notification sent on May 8, 2024. The incident involved unauthorized access to systems between April 18 and 23, 2023, affecting approximately 2.5 million individuals. The breach compromised protected health information (PHI), Social Security numbers, driver's license numbers, and financial account data. WebTPA, a healthcare administrator, secured its network and engaged third-party forensic experts.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7698b08dbb41bf5fWashington State AGfiled 2024-05-08(75d gap)Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2024/WebTPAEmployerServicesLLC.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2024
- Raw hash
- 7a454e2127df55c2a49e0e8890c375756c3431df6bc860375e108af5b491319b
Reporting entity
- Name
- WebTPAnorm: webtpa
- Domain
- webtpa.com
- Industry
- Healthcare Administration
Victim entity
- Name
- WebTPAnorm: webtpa
- Domain
- webtpa.com
- Industry
- Healthcare Administration
Incident
- Discovered
- Dec 28, 2023
- Materiality determined
- May 8, 2024
- Notification sent
- May 8, 2024
- Affected individuals
- 2,500,000
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with South Carolina Department of Consumer Affairs
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(207 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.