DisclosureLens
Leak SiteSEC 10-K Item 1CUnverified claim2 filings · 1 stateLifecycle stage 1 of 3: Unverified claimUnverified claimConfirmedEnforcedcl0p
Merged incident · 2 filings

UNITEDHEALTH GROUP INCORPORATED

Clustered 2 filings across 2 jurisdictions · filing window Jun 14, 2023 Feb 28, 2024. View entity profile → Other incidents for this victim →

Agreement not assessableMerge100%

Determination

Unverified claim

Members

2 filings

States

1

Affected · reported

First → last filing

Jun 14, 2023 Feb 28, 2024

Merge confidence

100%

incident inc_8cf3d72210784e3e · merged by human · confidence 100%

Unverified threat-actor claim — not a regulatory filing

Attribution, victim identity, and counts shown here derive from a threat actor's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Litigation Timing

Filing span
259days

Time between earliest and latest filing

Not recorded for this incident

Discovery variance · Leak precedence · Materiality delta · SEC filing delayneeds two dated filings.

Regulatory clocksLeak gap Leak >180dFull clock table in Litigation Timeline

Incident timeline

? — ?breach window unknown
Feb 28, 2024first & only filing
watching for filings

No discovery date is recorded on any filing in this cluster, so the notification delay is not computable. Dashed segments fill in as filings merge.

Member cascade — every filing about this breach

  1. JUN 14Leak sitecl0p postfirst filing · attacker claim · unverifiedday 0
  2. FEB 28SEC 10-K Item 1CSEC 10-K Item 1C noticemost recent · no count stated+259d
  3. Watching for additional filings — new sources merge into this incident automatically.

Roll-up facts — reconciled across members

Breach window
Discovered

Each fact cites the member filing that establishes it; when filings conflict, every value shows with its source.

Evidence ladder — rungs this incident occupies

Leak-site claim1 member

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

No press coverage linked yet.

State AG / regulator filing

No regulator filing linked yet.

SEC 8-K / victim statement1 member

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Merge provenance

Method
human
Confidence
1.00 · above the 0.85 auto-merge floor
Reviewed
operator-reviewed Jun 24, 2026 · at least one link edge was human-adjudicated
Audit
Every link edge records its method, confidence and model + prompt versions (100% is the strongest edge).

Merges are reversible — a wrong link can be detached with its audit trail intact. How merging works.

Filing velocity

Spread

259 days

vs. multi-state median

32.4× slower

About this clustering

DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. This page states only what the linked filings agree on; each filing's own account stays on its own record, linked from the timeline below.

The weekly clock on records like this one

The Disclosure Clock is a weekly briefing on what landed in the disclosure record, and the gap between the criminals' post and the regulator's filing — measured on the whole record, with the method shown.

Weekly. Double opt-in, one-click unsubscribe, and the address goes nowhere else.