Welltok
bd_db6e6d3e58b51e90 · schema v1 · pii pii-v1
Full breach record for Welltok →Welltok, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a breach of its MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok detected the compromise on July 26, 2023, and confirmed the breach on August 11, 2023. The incident affected approximately 642 New Hampshire residents, whose personal information (including names, addresses, and potentially government IDs) was exposed. Welltok engaged third-party cybersecurity specialists, offered credit monitoring via Experian, and is reviewing its privacy policies.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_0328ea1fdab9c459Maine State AGfiled 2023-12-22Verified by operator
- bd_5e4b7107bd1176deCalifornia State AGfiled 2023-12-22Verified
- bd_8ca9e17ac4dfbe9bVermont State AGfiled 2023-12-22Verified
- bd_063b1deb8c7a2bffMaine State AGfiled 2023-12-15(7d gap)Verified by operator
Show 6 more filings ↓Show fewer ↑up to 29d gap
- bd_69d99adc86ef4dcfVermont State AGfiled 2023-12-15(7d gap)Verified
- bd_b765e398c9850ca1California State AGfiled 2023-12-15(7d gap)Verified
- bd_e5a605be617ae396New Hampshire State AGfiled 2023-12-15(7d gap)Verified
- bd_e378dc71f9be8ac0Maine State AGfiled 2023-12-05(17d gap)Verified by operator
- bd_f5d34ac976e2a29fNew Hampshire State AGfiled 2023-12-05(17d gap)Verified
- bd_f45541c4fa22d1ebMaine State AGfiled 2023-11-23(29d gap)Verified by operator
Showing first 10 of 16 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/welltok-20231222.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2023
- Raw hash
- 94890cd8b19253fc858b2aa1222b1fe4162327cb9f696f082a882cbf27f2ff63
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- Aug 11, 2023
- Notification sent
- Dec 22, 2023
- Affected individuals
- 642
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(149 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.