HackingVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Delta Dental
bd_ed716715756a4072 · schema v1 · pii pii-v1
Full breach record for Delta Dental →Delta Dental of California and affiliates experienced a data security incident involving the MOVEit Transfer software. Unauthorized actors exploited a previously unknown vulnerability in the software between May 27 and May 30, 2023. The company discovered the incident on June 1, 2023. Personal information, including PHI and PII, was accessed and acquired without authorization. The company engaged forensic experts, notified law enforcement, and is offering 24 months of identity monitoring to affected individuals.
California clockDiscovered Jun 1, 2023 → Notified Nov 27, 2023179d ✗ CA 60-day late41 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_f9dd9d8c0025c2d4Vermont State AGfiled 2024-02-09(34d gap)Verified
- bd_84d913a18ea5d62dCalifornia State AGfiled 2024-01-31(43d gap)Candidate
- bd_9e88312a77fdbd76New Hampshire State AGfiled 2024-01-24(50d gap)Verified
- bd_b7d1eba67d9b0325California State AGfiled 2023-12-14(91d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582446
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2024
- Raw hash
- 69f8a1762f9a7b43b6bf1d0eeac6c18550a01d6f393a910548461eed31450e0f
Reporting entity
- Name
- Delta Dentalnorm: delta dental
- Domain
- www1.deltadentalins.com
Victim entity
- Name
- Delta Dentalnorm: delta dental
- Domain
- www1.deltadentalins.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Nov 27, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 weeks(287 days from discovery to filing)
- Compliance flags
- CA 60-day late · 179d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 1, 2023→ Notified: Nov 27, 2023179d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.