HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMINORMediumContained
Cierant
bd_dc825fbbaeb958ce · schema v1 · pii pii-v1
Full breach record for Cierant →Cierant Corporation disclosed a data security event where an unauthorized actor exploited a vulnerability in the third-party Cleo VLTrader secure file transfer tool. The incident was discovered on December 10, 2024, with the breach occurring on December 9, 2024. Affected data included PHI such as names, addresses, dates of birth, treatment dates, provider names, and medical record numbers for health plan members, including minors. No SSNs or financial information were involved. Cierant ceased use of the tool, rotated passwords, and enhanced security controls.
California clockDiscovered Dec 10, 2024 → Notified Jul 3, 2025205d ✗ CA 60-day late30 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_154646e20b01c5dbMontana State AGfiled 2025-07-07Candidate
- bd_15d0ae25a9674afdWashington State AGfiled 2025-07-07Verified
- bd_3dde15084b7b9d42Washington State AGfiled 2025-07-07Verified
- bd_d4221b679ab06c8dMontana State AGfiled 2025-07-07Candidate
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_a2f1dac33b9456dfTexas State AGfiled 2025-07-08(1d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605101
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2025
- Raw hash
- 5c68732810a5b69c6045c4cc71bc5fc6298e5eb479a50be7a5c5295b3079e0e4
Reporting entity
- Name
- Cierantnorm: cierant
- Domain
- cierant.com
Victim entity
- Name
- Cierantnorm: cierant
- Domain
- cierant.com
Incident
- Discovered
- Dec 10, 2024
- Materiality determined
- —
- Notification sent
- Jul 3, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICMINOR
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Reported the event to federal law enforcementNotifying relevant regulators
- Third party
- via Cleo
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 30 weeks(209 days from discovery to filing)
- Compliance flags
- CA 60-day late · 205dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 10, 2024→ Notified: Jul 3, 2025205d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.