Welltok
ent_bc2baf2307e8e3836749ebe0
Disclosures
25+
State AG · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
495,331
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Welltok
- Normalized
- welltok— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- welltok.com
Disclosure history (newest 25)newest first
- 🌴South Carolina State AGas victim2024-05-24
Welltok, Inc. notified South Carolina residents of a data breach involving its MOVEit Transfer server. An unknown actor exploited software vulnerabilities on May 30, 2023, to access the server and exfiltrate data including names, health information, and insurance details. Welltok engaged third-party cybersecurity specialists and is offering 12 months of credit monitoring.
- ⛰️New Hampshire State AGas reporting2024-04-03
Welltok, Inc. reported a cybersecurity incident involving the MOVEit Transfer server for Anthem Blue Cross Blue Shield. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok discovered the breach on August 11, 2023, after a third-party investigation. Approximately 4 New Hampshire residents were notified on January 23, 2024. Data types included identity and government identifiers. Welltok provided credit monitoring via Experian.
- 🦞Maine State AGas reporting2024-04-03
Welltok Inc filed a Maine Attorney General data breach notice regarding an external system breach (hacking) occurring on May 30, 2023, discovered on August 11, 2023. The incident affected 25 individuals, including 2 Maine residents. Welltok, acting as a business associate on behalf of a covered entity, provided written notification and offered credit monitoring and identity theft protection services.
- 🍁Vermont State AGas reporting2024-03-22
Welltok, Inc. notified Entergy Corporation Companies' Benefits Plus Medical Plan of a data breach involving its MOVEit Transfer server. An unknown actor accessed the server on May 30, 2023, exfiltrating names and other data. Welltok engaged cybersecurity specialists, enhanced privacy policies, and offered Experian credit monitoring to affected individuals.
- 🐻California State AGas victim2024-02-28
Welltok, Inc. disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names, treatment information, diagnoses, provider names, patient IDs, and health insurance information. The incident was discovered on July 26, 2023. Welltok engaged third-party cybersecurity specialists and is offering 12 months of credit monitoring to affected individuals.
- 🐻California State AGas reporting2024-01-08
Welltok, Inc., a healthcare technology vendor, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names, dates of birth, and health insurance information. The incident was discovered on July 26, 2023. Welltok is offering credit monitoring to affected individuals.
- 🐻California State AGas reporting2024-01-04
Welltok, Inc., a third-party service provider for Blue Shield of California, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023. The incident affects Blue Shield members. Welltok is offering credit monitoring services.
- 🦞Maine State AGas victim2023-12-22
Welltok, Inc., a business associate, reported an external system breach that occurred on May 30, 2023, and was discovered on September 22, 2023. The breach compromised the names and Social Security Numbers of 396 Maine residents. Notifications to affected individuals began on November 13, 2023.
- 🐻California State AGas victim2023-12-22
Welltok, Inc. disclosed that an unknown actor exploited a zero-day vulnerability in Progress Software's MOVEit Transfer tool between May 30-31, 2023, exfiltrating data including names, addresses, phone numbers, Member IDs, DOB/Age, Medicaid IDs, and plan types. Welltok learned of the potential impact on July 26, 2023, and confirmed the breach on August 11, 2023. The company engaged third-party cybersecurity specialists and is offering 24 months of credit monitoring via Experian.
- 🍁Vermont State AGas victim2023-12-22
Welltok, Inc. notified consumers of a data breach involving its MOVEit Transfer server, a third-party tool used to manage data for OSF Healthcare. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated personal information, including names. Welltok engaged third-party cybersecurity specialists and is offering credit monitoring services to affected individuals.
- 💎Delaware State AGas reporting2023-12-22
Welltok, Inc. notified UnitedHealthcare members in Delaware of a data breach involving the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer tool. The incident occurred between May 30-31, 2023, resulting in the exfiltration of member data including names, addresses, Member IDs, DOBs, and Medicaid IDs. Welltok engaged third-party forensic specialists and is offering 24 months of credit monitoring via Experian.
- ⛰️New Hampshire State AGas victim2023-12-22
Welltok, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a breach of its MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok detected the compromise on July 26, 2023, and confirmed the breach on August 11, 2023. The incident affected approximately 642 New Hampshire residents, whose personal information (including names, addresses, and potentially government IDs) was exposed. Welltok engaged third-party cybersecurity specialists, offered credit monitoring via Experian, and is reviewing its privacy policies.
- 🦞Maine State AGas victim2023-12-15
Welltok, Inc. filed a state AG breach notice for an external system breach (hacking) occurring on 05/30/2023 and discovered on 09/22/2023. The incident affected 495,331 individuals, including 26 Maine residents. Acquired data included names and Social Security Numbers. Welltok provided written notification and offered 12-24 months of credit monitoring and identity theft protection.
- 🍁Vermont State AGas victim2023-12-15
Welltok, Inc. disclosed a breach of its MOVEit Transfer server exploited via software vulnerabilities. An unknown actor accessed the server on May 30, 2023, and exfiltrated data including names, dates of birth, insurance IDs, and health information. Welltok notified affected individuals in December 2023, offering credit monitoring and identity restoration services.
- 🐻California State AGas victim2023-12-15
Welltok, Inc. disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names, dates of birth, phone numbers, treatment/diagnosis information, prescription information, provider names, medical record numbers, and health insurance information. The company was alerted to the compromise on July 26, 2023, and confirmed the breach on August 11, 2023. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and is offering 12 months of credit monitoring via Experian to affected individuals. The incident impacts residents of California and Rhode Island, among others.
- ⛰️New Hampshire State AGas victim2023-12-15
Welltok, Inc. issued a supplemental notice to New Hampshire residents regarding a cybersecurity incident involving the MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok discovered the compromise on August 11, 2023, and notified affected individuals on December 13, 2023. Approximately 21 New Hampshire residents were impacted. The incident involved personal and government-issued identification data. Welltok engaged third-party cybersecurity specialists and provided credit monitoring services through Experian.
- 💎Delaware State AGas reporting2023-12-14
Welltok, Inc. notified Cohere Health customers of a data breach involving the MOVEit Transfer server. An unknown actor exploited a vulnerability in the software on May 30, 2023, accessing and exfiltrating data including names, DOB, SSNs, and PHI. Welltok discovered the compromise on July 26, 2023, after applying patches. Approximately 1,345 Rhode Island residents were identified as affected. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and offered credit monitoring and identity restoration services.
- 🐻California State AGas reporting2023-12-05
Welltok, Inc., a service provider for Elixir Pharmacy, disclosed that an unknown actor exploited software vulnerabilities in a MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023, after investigating published vulnerabilities. The incident affected patients of Elixir Pharmacy. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and is offering credit monitoring services to affected individuals.
- 🦞Maine State AGas victim2023-12-05
Welltok, Inc., a business associate for multiple healthcare entities, reported an external system breach that occurred on May 30, 2023. The breach, discovered on September 22, 2023, impacted 53 Maine residents. The compromised information includes names and Social Security numbers. In response, Welltok offered 24 months of credit monitoring and identity restoration services through Experian.
- ⛰️New Hampshire State AGas victim2023-12-05
Welltok, Inc. notified New Hampshire residents of a breach involving its MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data. Welltok discovered the incident on August 11, 2023, and sent notifications to approximately 116 NH residents on December 4, 2023. Impacted data included names, addresses, SSNs, DOBs, and health information. Welltok engaged third-party cybersecurity specialists and offered credit monitoring via Experian.
- 🦞Maine State AGas victim2023-11-23
Healthcare business associate Welltok, Inc. reported a data breach affecting 426,812 individuals, stemming from the MOVEit vulnerability. The incident occurred on May 30, 2023, and was discovered on October 23, 2023. Compromised data includes names and Social Security Numbers. Welltok notified affected individuals on November 22, 2023, and is offering 12 to 24 months of credit monitoring and identity restoration services through Experian.
- 🍁Vermont State AGas reporting2023-11-22
Welltok, Inc. notified Graphic Packaging International that an unknown actor exploited vulnerabilities in the MOVEit Transfer server on May 30, 2023, to exfiltrate data including names and government IDs. The incident was discovered on July 26, 2023, and notifications were sent in November 2023. Welltok engaged third-party cybersecurity specialists and is offering credit monitoring services.
- 🍁Vermont State AGas reporting2023-11-22
Welltok, Inc. notified Premier Health patients of a data breach involving the MOVEit Transfer server. An unknown actor exploited software vulnerabilities on May 30, 2023, to exfiltrate data including names and government identifiers. Welltok engaged third-party cybersecurity specialists and is offering credit monitoring services. The incident was discovered on August 11, 2023.
- 🐻California State AGas reporting2023-11-22
Welltok, Inc., a wellness program provider for Graphic Packaging International, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. The incident was discovered on July 26, 2023. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and is offering credit monitoring to affected individuals. The breach affects residents of California and Rhode Island, among others.
- ⛰️New Hampshire State AGas victim2023-11-22
Welltok, Inc. notified New Hampshire residents that an unknown actor exploited vulnerabilities in the MOVEit Transfer server on May 30, 2023, to exfiltrate data. Welltok discovered the compromise on July 26, 2023, and confirmed the breach on August 11, 2023. Approximately 363 New Hampshire residents were affected. Welltok engaged third-party cybersecurity specialists, offered credit monitoring via Experian, and enhanced privacy policies.