Welltok
bd_e5a605be617ae396 · schema v1 · pii pii-v1
Full breach record for Welltok →Welltok, Inc. issued a supplemental notice to New Hampshire residents regarding a cybersecurity incident involving the MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok discovered the compromise on August 11, 2023, and notified affected individuals on December 13, 2023. Approximately 21 New Hampshire residents were impacted. The incident involved personal and government-issued identification data. Welltok engaged third-party cybersecurity specialists and provided credit monitoring services through Experian.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_063b1deb8c7a2bffMaine State AGfiled 2023-12-15Verified by operator
- bd_69d99adc86ef4dcfVermont State AGfiled 2023-12-15Verified
- bd_b765e398c9850ca1California State AGfiled 2023-12-15Verified
- bd_0328ea1fdab9c459Maine State AGfiled 2023-12-22(7d gap)Verified by operator
Show 6 more filings ↓Show fewer ↑up to 22d gap
- bd_5e4b7107bd1176deCalifornia State AGfiled 2023-12-22(7d gap)Verified
- bd_8ca9e17ac4dfbe9bVermont State AGfiled 2023-12-22(7d gap)Verified
- bd_db6e6d3e58b51e90New Hampshire State AGfiled 2023-12-22(7d gap)Verified
- bd_e378dc71f9be8ac0Maine State AGfiled 2023-12-05(10d gap)Verified by operator
- bd_f5d34ac976e2a29fNew Hampshire State AGfiled 2023-12-05(10d gap)Verified
- bd_f45541c4fa22d1ebMaine State AGfiled 2023-11-23(22d gap)Verified by operator
Showing first 10 of 16 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/welltok-20231215.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2023
- Raw hash
- f2559d9841346bd2769fad49123e38b4f56cf3480b6a2a124d99a06a72534b46
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Incident
- Discovered
- Aug 11, 2023
- Materiality determined
- —
- Notification sent
- Dec 13, 2023
- Affected individuals
- 21
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.