HackingVulnerability ExploitStolen CredentialsData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedN-DayIDENTITY_BASICLowContained
Elixir Pharmacy
bd_b8f67070c4cc8147 · schema v1 · pii pii-v1
Full breach record for Elixir Pharmacy →Welltok, Inc., a service provider for Elixir Pharmacy, disclosed that an unknown actor exploited software vulnerabilities in a MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023, after investigating published vulnerabilities. The incident affected patients of Elixir Pharmacy. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and is offering credit monitoring services to affected individuals.
California clockDiscovered Jul 26, 2023 → Notified Dec 4, 2023131d ✗ CA 60-day late19 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577467
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 5, 2023
- Raw hash
- 221e834ef4e98691226918921f1bf5e093afb977e03f49ba382e5fa08ca1d26f
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Elixir Pharmacynorm: elixir pharmacy
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- —
- Notification sent
- Dec 4, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Welltok, Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(132 days from discovery to filing)
- Compliance flags
- CA 60-day late · 131d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 26, 2023→ Notified: Dec 4, 2023131d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.