DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainIdentity (basic)Government IDPHIHealth (basic)HighContained

WELLPOINT WASHINGTON, INC.

bd_ec5cf7ef81db44cb · schema v1 · pii pii-v1

Severity

High

Discovered

Mar 2, 2026

Filed

Jun 2, 2026

To disclose

13 weeks

Affected

12,017state residents only

Confidence

71%
Full breach record for WELLPOINT WASHINGTON, INC.2 incidents on file

Wellpoint Washington, Inc. reported a phishing incident affecting 12,017 Washington residents. The breach occurred June 24-July 2, 2025, involving unauthorized access to an email account via a phishing attack by business associate Clinics of Washington. Wellpoint discovered the incident on March 2, 2026. Exposed data included PHI, SSNs, DOBs, and driver's licenses. Remediation included credit monitoring services.

Washington clock WA AG >90d13 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 251 days
discovery → filing · 13 weeks / 92 days

Jun 24, 2025

Begins

Mar 2, 2026

Discovered

Jun 2, 2026

Filed

vs. sector median

+2 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed12,017 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.