HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Welltok
bd_f5d34ac976e2a29f · schema v1 · pii pii-v1
Full breach record for Welltok →Welltok, Inc. notified New Hampshire residents of a breach involving its MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok discovered the incident on August 11, 2023, and sent notifications to approximately 116 NH residents on December 4, 2023. Impacted data included names, addresses, SSNs, DOBs, and health information. Welltok engaged third-party cybersecurity specialists and offered credit monitoring via Experian.
This filing is one of 17 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_e378dc71f9be8ac0Maine State AGfiled 2023-12-05Verified by operator
- bd_063b1deb8c7a2bffMaine State AGfiled 2023-12-15(10d gap)Verified by operator
- bd_69d99adc86ef4dcfVermont State AGfiled 2023-12-15(10d gap)Verified
- bd_b765e398c9850ca1California State AGfiled 2023-12-15(10d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 17d gap
- bd_e5a605be617ae396New Hampshire State AGfiled 2023-12-15(10d gap)Verified
- bd_f45541c4fa22d1ebMaine State AGfiled 2023-11-23(12d gap)Verified by operator
- bd_0328ea1fdab9c459Maine State AGfiled 2023-12-22(17d gap)Verified by operator
- bd_5e4b7107bd1176deCalifornia State AGfiled 2023-12-22(17d gap)Verified
- bd_8ca9e17ac4dfbe9bVermont State AGfiled 2023-12-22(17d gap)Verified
- bd_db6e6d3e58b51e90New Hampshire State AGfiled 2023-12-22(17d gap)Verified
Showing first 10 of 16 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/welltok-20231205.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 5, 2023
- Raw hash
- 6895eb9cfc05df1c35dcb0723ab82980eee36bf557ca8f6abacdd5c09a57d637
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Incident
- Discovered
- Aug 11, 2023
- Materiality determined
- —
- Notification sent
- Dec 4, 2023
- Affected individuals
- 116
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.