HackingData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
NationsBenefits Holdings, LLC
bd_e00425fe19d51b10 · schema v1 · pii pii-v1
Full breach record for NationsBenefits Holdings, LLC →NationsBenefits Holding, LLC, a benefits administration provider, disclosed a cybersecurity incident involving its third-party file exchange vendor, Fortra, LLC. The attack occurred on or around January 30, 2023, and NationsBenefits discovered the incident on February 7, 2023. The breach potentially exposed personal information of individuals covered by health plan clients. NationsBenefits engaged legal counsel and cybersecurity firms, notified law enforcement, and offered 24 months of credit monitoring via Experian.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1b538b7a6b069a1eVermont State AGfiled 2023-04-13Verified
- bd_27eb698b3f802e52Montana State AGfiled 2023-04-13Candidate
- bd_7a3042e338cc1200New Hampshire State AGfiled 2023-04-13Verified
- bd_5cf8474b7cde8f07California State AGfiled 2023-04-14(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 22d gap
- bd_90ff9cd7813fad7cOregon State AGfiled 2023-05-01(18d gap)Verified
- bd_be7b07047f2e066aMaine State AGfiled 2023-05-05(22d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/04/NationsBenefits-Incident-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 13, 2023
- Raw hash
- b3393ecce1993fa148c80191d2ebb26abd6991af4f37fd3fb4c1d973f250903f
Reporting entity
- Name
- NationsBenefits Holdings, LLCnorm: nationsbenefits holdings
Victim entity
- Name
- NationsBenefits Holdings, LLCnorm: nationsbenefits holdings
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Fortra, LLC
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.