Cierant
bd_dc825fbbaeb958ce · schema v1 · pii pii-v1
Full breach record for Cierant →Cierant Corporation disclosed a data security event where an unauthorized actor exploited a vulnerability in the third-party Cleo VLTrader secure file transfer tool. The incident was discovered on December 10, 2024, with the breach occurring on December 9, 2024. Affected data included PHI such as names, addresses, dates of birth, treatment dates, provider names, and medical record numbers for health plan members, including minors. No SSNs or financial information were involved. Cierant ceased use of the tool, rotated passwords, and enhanced security controls.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 9, 2024
Begins
Dec 10, 2024
Discovered
Jul 7, 2025
Filed
vs. sector median
+11 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_07daf6a1b38451a92025-02-01 · +155dVerified by operator
Regulatory filings (7) · sorted by filing gap
- Montana State AGbd_154646e20b01c5db2025-07-07Verified
- Washington State AGbd_15d0ae25a9674afd2025-07-07Verified
- Washington State AGbd_3dde15084b7b9d422025-07-07Verified
- Montana State AGbd_d4221b679ab06c8d2025-07-07Verified
Show 3 more filings ↓Show fewer ↑up to 6d gap
- Texas State AGbd_a2f1dac33b9456df2025-07-08 · +1dVerified
- HHS OCRbd_af706982660950002025-07-03 · +4dVerified by operator
- Illinois State AGbd_f1e6a8237f126a062025-07-01 · +6dCandidate
Filing propagation · 8 filings · 6 states
View merged incident ↗Pattern: first filing Jul 1 (IL), last Jul 8 (TX) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.