DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Delaware Life

bd_a2dc163aa1d246e3 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 1, 2019

Filed

Jun 24, 2019

To disclose

12 weeks

Affected

107state residents only

Confidence

66%
Full breach record for Delaware Life5 incidents on file

Delaware Life Insurance Company notified the NH Attorney General that a third-party vendor, Mediant Communications, suffered a breach on April 1, 2019, when an unknown malicious party exploited a vulnerability in Mediant's email software to access four business email accounts. The incident affected 107 New Hampshire residents, exposing names, addresses, dates of birth, Social Security numbers, and account/policy numbers. Mediant engaged forensic investigators, contained the incident by disconnecting servers, and reported to the FBI. Delaware Life sent notices on June 19, 2019, and offered two years of credit monitoring.

Incident timeline

discovery → filing · 12 weeks / 84 days

Apr 1, 2019

Begins

Apr 1, 2019

Discovered

Jun 24, 2019

Filed

vs. sector median

+4 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed107 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.