Blue Shield of California
bd_a6884d47e386af7d · schema v1 · pii pii-v1
Welltok, Inc., a third-party service provider for Blue Shield of California, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023. The incident affects Blue Shield members. Welltok is offering credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 26, 2023
Discovered
Jan 4, 2024
Filed
vs. sector median
+14 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.