Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICPHIHEALTH_BASICMediumContained
Delta Dental of Virginia
bd_a1166220222f2703 · schema v1 · pii pii-v1
Full breach record for Delta Dental of Virginia →Delta Dental of Virginia notified the New Hampshire Attorney General on November 21, 2025, regarding a phishing incident affecting approximately 169 NH residents. Unauthorized access to an email account occurred between March 21 and April 23, 2025, exposing names, SSNs, government IDs, and PHI. DDVA engaged forensic experts, provided 12 months of TransUnion credit monitoring, and implemented enhanced employee safeguards.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_258b7419633efa29HHS OCRfiled 2025-11-21Verified
- bd_33adf66631ec6cffTexas State AGfiled 2025-11-21Verified
- bd_63884c8a32550403California State AGfiled 2025-11-21Verified
- bd_6c4632d1958d0b22Vermont State AGfiled 2025-11-21Verified
Show 3 more filings ↓Show fewer ↑
- bd_77514f3f8810054eSouth Carolina State AGfiled 2025-11-21Verified
- bd_b83003f69cbe723dIndiana State AGfiled 2025-11-21Verified
- bd_bf99bf0f3544346bMaine State AGfiled 2025-11-21Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/delta-dental-virginia-20251121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2025
- Raw hash
- b8363bf255d98dcb407190f959c1af6999eaef85df4cb895fe8e20b4ad4a82b3
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Delta Dental of Virginianorm: delta dental of virginia
Incident
- Discovered
- Apr 23, 2025
- Materiality determined
- —
- Notification sent
- Nov 21, 2025
- Affected individuals
- 169
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.