HackingStolen CredentialsCustomer Data InvolvedTargetedPIIFINANCIAL_ACCOUNTLowContained
Solutran
bd_fbf40114dcb89387 · schema v1 · pii pii-v1
Full breach record for Solutran →Solutran, part of Optum Financial Services, reported unauthorized access to member web portals starting around January 13, 2023. The attacker used valid login credentials to access Healthy Benefits accounts, likely to misuse monetary benefits on prepaid cards. Solutran detected the breach on February 15, 2023, and contained it by enforcing password resets and enhancing security controls. No SSN, driver's license, or medical diagnosis data was exposed.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_173a16c3057df866HHS OCRfiled 2023-05-12Verified
- bd_efbdb1fc019f7ae0Montana State AGfiled 2023-05-12Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/solutran-20230512.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 12, 2023
- Raw hash
- 7209e5d78f214990c57780c81d91127d3a2a9450e25588e62c76c4adbaf45f96
Reporting entity
- Name
- Solutrannorm: solutran
Victim entity
- Name
- Solutrannorm: solutran
Incident
- Discovered
- Feb 15, 2023
- Materiality determined
- Feb 19, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.