HackingVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Delta Dental
bd_b7d1eba67d9b0325 · schema v1 · pii pii-v1
Full breach record for Delta Dental →Delta Dental of California and affiliates experienced a data security incident involving the MOVEit Transfer software. Unauthorized actors exploited a previously unknown vulnerability in the software between May 27 and May 30, 2023. The company discovered the incident on June 1, 2023. Personal information, including names, addresses, and potentially health/financial data, was accessed and acquired without authorization. The company engaged forensic experts, notified law enforcement, and is offering 24 months of identity monitoring to affected individuals.
California clockDiscovered Jun 1, 2023 → Notified Nov 27, 2023179d ✗ CA 60-day late28 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_9e88312a77fdbd76New Hampshire State AGfiled 2024-01-24(41d gap)Verified
- bd_84d913a18ea5d62dCalifornia State AGfiled 2024-01-31(48d gap)Candidate
- bd_f9dd9d8c0025c2d4Vermont State AGfiled 2024-02-09(57d gap)Verified
- bd_ed716715756a4072California State AGfiled 2024-03-14(91d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577908
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 14, 2023
- Raw hash
- 5ae668bdfe30bde69d7e3279d5c932b7df9da13c08be036daa153948d41569e1
Reporting entity
- Name
- Delta Dentalnorm: delta dental
- Domain
- www1.deltadentalins.com
Victim entity
- Name
- Delta Dentalnorm: delta dental
- Domain
- www1.deltadentalins.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Nov 27, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 weeks(196 days from discovery to filing)
- Compliance flags
- CA 60-day late · 179d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 1, 2023→ Notified: Nov 27, 2023179d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.