Welltok, Inc. notified Graphic Packaging International that an unknown actor exploited vulnerabilities in the MOVEit Transfer server on May 30, 2023, to exfiltrate data including names and government IDs. The incident was discovered on July 26, 2023, and notifications were sent in November 2023. Welltok engaged third-party cybersecurity specialists and is offering credit monitoring services.