MalwareRansomwareData ExfiltratedData EncryptedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Delaware Life
bd_ed51ded19bb66eb1 · schema v1 · pii pii-v1
Full breach record for Delaware Life →Delaware Life Insurance Company notified policyholders of a ransomware incident discovered on February 9, 2023, involving the MOVEit Transfer software. The breach exposed names, addresses, DOBs, SSNs, and policy numbers. The company engaged forensic investigators, alerted the FBI, and offered 24 months of identity protection services. A separate May 2023 MOVEit incident was also referenced. Rhode Island residents were specifically identified as impacted.
Leak gap clock⏱ Leak >90d24 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
A leak claim by dispossessor about this victim predates this filing by 165 days.View originating leak claim
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/11/DLIC-Policyholder-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- d330200dca3e2ad99ab0f2dfb76455325ce378685f1fcefb86de55cc1caf449f
Reporting entity
- Name
- Delaware Lifenorm: delaware life
- Domain
- delawarelife.com
Victim entity
- Name
- Delaware Lifenorm: delaware life
- Domain
- delawarelife.com
Incident
- Discovered
- Feb 9, 2023
- Materiality determined
- —
- Notification sent
- Nov 21, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Alerted appropriate regulatory authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 weeks(169 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.