DisclosureLens
HackingHealthcareFinancial ServicesHealthcareVulnerability ExploitData ExfiltratedTargetedPIIIdentity (basic)Government IDHighContained

Delta Dental of California and Affiliates Company

bd_fbe53c814b9f6038 · schema v1 · pii pii-v1

Severity

High

Discovered

Jun 1, 2023

Filed

Dec 14, 2023

To disclose

28 weeks

Affected

33,030state residents only

Confidence

64%

Delta Dental of California and Affiliates Company disclosed a data security incident involving the MOVEit Transfer software. Unauthorized actors exploited a vulnerability to access and acquire company information between May 27 and May 30, 2023. The company discovered the incident on June 1, 2023, and notified affected individuals starting November 27, 2023. Affected data included personal information. The company engaged forensic experts, patched the vulnerability, and offered 24 months of identity monitoring.

South Carolina clock SC CRA notice due28 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 5 days
discovery → filing · 28 weeks / 196 days

May 27, 2023

Begins

Jun 1, 2023

Discovered

Dec 14, 2023

Filed

vs. sector median

+15 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed33,030 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.